Описание
Security update for python-dynaconf
This update for python-dynaconf fixes the following issues:
Changes in python-dynaconf:
- CVE-2026-33154: Server-Side Template Injection in the @Jinja resolver (bsc#1260063)
Список пакетов
openSUSE Leap 16.0
python313-dynaconf-3.2.5-bp160.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1260063
- SUSE CVE CVE-2026-33154 page
Описание
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.
Затронутые продукты
openSUSE Leap 16.0:python313-dynaconf-3.2.5-bp160.2.1
Ссылки
- CVE-2026-33154
- SUSE Bug 1260063