rpm package
suse/brotli&distro=SUSE Linux Enterprise Micro 5.5
pkg:rpm/suse/brotli&distro=SUSE%20Linux%20Enterprise%20Micro%205.5
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-9086 | Hig | 7.5 | < 1.0.7-150200.3.5.1 | 1.0.7-150200.3.5.1 | Sep 12, 2025 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path | |
| CVE-2025-10148 | Med | 5.3 | < 1.0.7-150200.3.5.1 | 1.0.7-150200.3.5.1 | Sep 12, 2025 | curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traf |
- affected < 1.0.7-150200.3.5.1fixed 1.0.7-150200.3.5.1
1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path
- affected < 1.0.7-150200.3.5.1fixed 1.0.7-150200.3.5.1
curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traf