openSUSE Patches Two Longstanding PyYAML Flaws in Tumbleweed Python Packages
openSUSE has published advisory openSUSE-SU-2026:11996-1, rated moderate, covering two vulnerabilities fixed in the PyYAML packages shipped on openSUSE Tumbleweed GA media. The update delivers python313-PyYAML 6.0.3-1.6 and python314-PyYAML 6.0.3-1.6, resolving CVE-2017-18342 and CVE-2020-14343. SUSE scores CVE-2017-18342 at 7.4 and CVE-2020-14343 at 8.8 under CVSS. PyYAML is among the most widely used Python libraries for parsing configuration and data files, so the affected packages are likely present on build servers, containers and developer workstations running Tumbleweed. openSUSE Tumbleweed is the only product listed as affected.
The advisory does not publish exploitation details for either flaw, and no proof-of-concept or attack chain is described. What the published scoring vectors do show is the shape of the exposure. CVE-2017-18342 is vectored AV:L/AC:H/PR:N/UI:N, indicating local access and high attack complexity, with full loss of confidentiality, integrity and availability where exploitation succeeds. CVE-2020-14343 is vectored AV:N/AC:L/PR:N/UI:R, reachable over the network at low complexity but requiring user interaction. Both are fixed in the 6.0.3-1.6 build now carried on GA media.
The exposure here comes from reach rather than novelty. Both CVEs are long-standing library issues that persist wherever an older PyYAML remains bundled in images, virtual environments or pipeline tooling, and the library sits deep in automation stacks that parse YAML from many sources. FIRST EPSS currently places CVE-2017-18342 at a 5.7% probability of exploitation within the next 30 days and CVE-2020-14343 at 6.0%. Those figures are low in absolute terms but apply to a dependency present in a very large share of Python deployments.
Attack Surface
Endpoint OS, Server OS, Supply Chain (Third-party vendors)
Tactics
Execution, Initial Access
Techniques
- T1059.006 – Command and Scripting Interpreter: Python
- T1195.001 – Supply Chain Compromise: Compromise Software Dependencies and Development Tools
- T1203 – Exploitation for Client Execution
SuperPRO's Threat Countermeasures Procedures
- Apply the fixed packages on openSUSE Tumbleweed hosts: python313-PyYAML 6.0.3-1.6 and python314-PyYAML 6.0.3-1.6, for example with 'zypper refresh && zypper update python313-PyYAML python314-PyYAML'.
- Inventory affected systems with 'rpm -q python313-PyYAML python314-PyYAML' and treat any build earlier than 6.0.3-1.6 as carrying CVE-2017-18342 and CVE-2020-14343.
- Run 'zypper dup' on Tumbleweed systems that lag behind the current snapshot, since the corrected PyYAML build is delivered through the rolling distribution GA media named in openSUSE-SU-2026:11996-1.
- Rebuild container images, VM templates and installation media derived from openSUSE Tumbleweed GA media published before this release so they pick up PyYAML 6.0.3-1.6 instead of the superseded package.
- Schedule remediation first for Tumbleweed systems that accept externally supplied input, reflecting the network-reachable vector of CVE-2020-14343 (AV:N/AC:L/PR:N/UI:R) against the local-only vector of CVE-2017-18342 (AV:L/AC:H).
- Track the SUSE CVE pages for CVE-2017-18342 (https://www.suse.com/security/cve/CVE-2017-18342.html) and CVE-2020-14343 (https://www.suse.com/security/cve/CVE-2020-14343.html) for status changes or additional affected packages, and verify post-update package versions report 6.0.3-1.6 or later.