VDB
Sign up
HIGH8.8

PYSEC-2026-624

Cobbler Web Interface Lacks CSRF Protection

Quick fix

PYSEC-2026-624 — cobbler: upgrade to the fixed version with the command below.

pip install --upgrade 'cobbler>=2.6.0'

Details

cobbler: Web interface lacks CSRF protection when using Django framework

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/cobbler
Introduced in: 0Fixed in: 2.6.0
Fixpip install --upgrade 'cobbler>=2.6.0'

References