openSUSE Tumbleweed — python36-bottle — vulnerability — patch and remediation guide
🟡 Medium ⏱ 10–30 min Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read • Source: SUSE security advisory Related CVEs: CVE-2016-9964 Upstream summary: redirect() in bottle.py in bottle 0.12.10 doesn't filter a "rn" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233rnSet-Cookie: name=salt") call. Table of […]