rpm package
opensuse/yt-dlp&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/yt-dlp&distro=openSUSE%20Leap%2016.0
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-50574 | Hig | 8.3 | < 2026.06.09-bp160.1.1 | 2026.06.09-bp160.1.1 | Jun 23, 2026 | yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary | |
| CVE-2026-50023 | Hig | 8.3 | < 2026.06.09-bp160.1.1 | 2026.06.09-bp160.1.1 | Jun 23, 2026 | yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The | |
| CVE-2026-50019 | Med | 6.1 | < 2026.06.09-bp160.1.1 | 2026.06.09-bp160.1.1 | Jun 23, 2026 | yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download fragments differs from their parent manifest's. At |
- affected < 2026.06.09-bp160.1.1fixed 2026.06.09-bp160.1.1
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary
- affected < 2026.06.09-bp160.1.1fixed 2026.06.09-bp160.1.1
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The
- affected < 2026.06.09-bp160.1.1fixed 2026.06.09-bp160.1.1
yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download fragments differs from their parent manifest's. At