openSUSE 16 Security Update : agama-web-ui (openSUSE-SU-2026:21448-1)

critical Nessus Plugin ID 330583

Synopsis

The remote openSUSE host is missing one or more security updates.

Description

The remote openSUSE 16 host has a package installed that is affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21448-1 advisory.

- CVE-2025-7783: form-data: unsafe `Math.random()` function is used to select a boundary value for multipart form-encoded data (bsc#1246822).
- CVE-2026-12143: form-data: CRLF injection via unescaped multipart field names and filenames (bsc#1272310).
- CVE-2026-13149: brace-expansion: `expand()` function exhibits exponential-time complexity when processing non-expanding `{}` brace groups (bsc#1269927).
- CVE-2026-13311: shell-quote: quadratic complexity in `parse()` function when processing specially crafted strings (bsc#1269359).
- CVE-2026-13676: fast-uri: host-based policy bypass due to failure to canonicalize Unicode/IDN hostnames for HTTP-family URLs (bsc#1269595).
- CVE-2026-27601: underscore: DoS via stack overflow due to missing depth limits in `_.flatten` and `_.isEqual` functions (bsc#1259169).
- CVE-2026-40181: react-router: open redirect to an external domain due to path values starting with `//` being reinterpreted as protocol-relative URLs (bsc#1272311).
- CVE-2026-49356: @babel/core: arbitrary file read via `sourceMappingURL` comment (bsc#1272317).
- CVE-2026-53550: js-yaml: quadratic complexity in merge-key processing when processing a crafted YAML document (bsc#1268851).
- CVE-2026-53632: launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows (bsc#1272319).
- CVE-2026-54466: websocket-driver: message corruption via abuse of protocol length headers (bsc#1272312).
- CVE-2026-54490: websocket-driver: resource limit bypass via message compression (bsc#1272313).
- CVE-2026-55602: http-proxy-middleware: Host-header-driven backend routing bypass via `router` host+path substring matching (bsc#1272318).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected agama-web-ui package.

See Also

https://bugzilla.suse.com/1246822

https://bugzilla.suse.com/1259169

https://bugzilla.suse.com/1268851

https://bugzilla.suse.com/1269359

https://bugzilla.suse.com/1269514

https://bugzilla.suse.com/1269595

https://bugzilla.suse.com/1269927

https://bugzilla.suse.com/1272310

https://bugzilla.suse.com/1272311

https://bugzilla.suse.com/1272312

https://bugzilla.suse.com/1272313

https://bugzilla.suse.com/1272317

https://bugzilla.suse.com/1272318

https://bugzilla.suse.com/1272319

https://www.suse.com/security/cve/CVE-2025-7783

https://www.suse.com/security/cve/CVE-2026-12143

https://www.suse.com/security/cve/CVE-2026-13149

https://www.suse.com/security/cve/CVE-2026-13311

https://www.suse.com/security/cve/CVE-2026-13676

https://www.suse.com/security/cve/CVE-2026-27601

https://www.suse.com/security/cve/CVE-2026-40181

https://www.suse.com/security/cve/CVE-2026-49356

https://www.suse.com/security/cve/CVE-2026-53550

https://www.suse.com/security/cve/CVE-2026-53632

https://www.suse.com/security/cve/CVE-2026-54466

https://www.suse.com/security/cve/CVE-2026-54490

https://www.suse.com/security/cve/CVE-2026-55602

Plugin Details

Severity: Critical

ID: 330583

File Name: openSUSE-2026-21448-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/29/2026

Updated: 7/29/2026

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

Percentile: 96.39

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-55602

CVSS v3

Risk Factor: High

Base Score: 8.6

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.4

Threat Score: 8.9

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

CVSS Score Source: CVE-2025-7783

Vulnerability Information

CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:agama-web-ui

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/27/2026

Vulnerability Publication Date: 7/18/2025

Reference Information

CVE: CVE-2025-7783, CVE-2026-12143, CVE-2026-13149, CVE-2026-13311, CVE-2026-13676, CVE-2026-27601, CVE-2026-40181, CVE-2026-49356, CVE-2026-53550, CVE-2026-53632, CVE-2026-54466, CVE-2026-54490, CVE-2026-55602