MGASA-2026-0377

Source
https://advisories.mageia.org/MGASA-2026-0377.html
Import Source
https://advisories.mageia.org/MGASA-2026-0377.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2026-0377
Upstream
Published
2026-09-05T04:35:57Z
Modified
2026-09-05T04:45:04Z
Summary
Updated python-linkify-it-py package fixes security vulnerabilities
Details

LinkifyIt.match() was quadratic on untrusted input when linkify is enabled (GHSA-8m2q-wq3r-6hq8). Fix quadratic complexity in LinkifyIt.match(), port of linkify-it 5.0.1 and 5.0.2 (upstream CVE-2026-48801, CVE-2026-59887) (#82) Match validators at a position instead of slicing the tail, needed because Python 3.10 does not optimize the ^ anchor (#82) Allow ; in the email name, matching linkify-it. Behavior change: a;b@example.com is now linkified (#82)

References
Credits

Affected packages

Mageia:10 / python-linkify-it-py

Package

Name
python-linkify-it-py
Purl
pkg:rpm/mageia/python-linkify-it-py?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.1-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0377.json"