openSUSE Tumbleweed — cockpit — multiple vulnerabilities (4 CVEs) — patch and remediation guide
🔴 Critical ⏱ 15–90 min Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read • Source: SUSE advisory RHSA-2026:7383 (see also SUSE bugzilla) Related CVEs: CVE-2026-4631 CVE-2026-4802 CVE-2025-13465 CVE-2024-6126 Upstream summary: Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation […]