Fedora has issued an advisory on March 11: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MUH4YM6G3UIVK2776BABUYJKVIBPTUT5/
CVE: (none) => CVE-2025-27516Source RPM: (none) => python-jinja2-3.1.5-2.mga10.src.rpm, python-jinja2-3.1.5-1.mga9.src.rpmStatus comment: (none) => Fixed upstream in 3.1.6Whiteboard: (none) => MGA9TOO
Suggested advisory: ======================== The updated package fixes a security vulnerability: Jinja sandbox breakout through attr filter selecting format method. (CVE-2025-27516) References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MUH4YM6G3UIVK2776BABUYJKVIBPTUT5/ ======================== Updated package in core/updates_testing: ======================== python3-jinja2-3.1.6-1.mga9 from SRPM: python-jinja2-3.1.6-1.mga9.src.rpm
Version: Cauldron => 9Status: NEW => ASSIGNEDStatus comment: Fixed upstream in 3.1.6 => (none)Whiteboard: MGA9TOO => (none)Assignee: bugsquad => qa-bugsSource RPM: python-jinja2-3.1.5-2.mga10.src.rpm, python-jinja2-3.1.5-1.mga9.src.rpm => python-jinja2-3.1.5-1.mga9.src.rpm
Keywords: (none) => advisory
RH x86_64 installing python3-jinja2-3.1.6-1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/1: python3-jinja2 ################################################################################################## 1/1: removing python3-jinja2-3.1.5-1.mga9.noarch ################################################################################################## Run the test referenced in bug#28461 comment#7 python jinja-test.py Hello. If you see this with no errors then it worked :)
CC: (none) => andrewsfarmWhiteboard: (none) => MGA9-64-OK
Validating.
CC: (none) => sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0094.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED