CVE-2026-18503: attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect
sniffing and consume significant CPU (bsc#1274683).
CVE-2026-19672: The tarfile module's tar and data extraction filters created directories outside the destination for
members whose name leaves the destination and retu (bsc#1276227).
Changes for python:
Update bundled setuptools wheels to setuptools-40.6.2-py2.py3-none-any.whl (bsc#1276903)