openSUSE Tumbleweed — qutebrowser — multiple vulnerabilities (3 CVEs) — patch and remediation guide
🔴 Critical ⏱ 15–90 min Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read • Source: SUSE advisory openSUSE-SU-2018:2120-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-10895 CVE-2018-1000559 CVE-2020-11054 Upstream summary: qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A […]