Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20429-1

Опубликовано: 25 мар. 2026
Источник: suse-cvrf

Описание

Security update for python-dynaconf

This update for python-dynaconf fixes the following issues:

Changes in python-dynaconf:

  • CVE-2026-33154: Server-Side Template Injection in the @Jinja resolver (bsc#1260063)

Список пакетов

openSUSE Leap 16.0
python313-dynaconf-3.2.5-bp160.2.1

Описание

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.


Затронутые продукты
openSUSE Leap 16.0:python313-dynaconf-3.2.5-bp160.2.1

Ссылки