SUSE-SU-2026:22655-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622655-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22655-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:22655-1
Upstream
Related
Published
2026-07-14T10:37:38Z
Modified
2026-07-17T18:24:04.909442220Z
Summary
Security update for python-mistune
Details

This update for python-mistune fixes the following issues

  • CVE-2026-59922: quadratic-time parsing on long runs of some markers in formatting.py can lead to DoS (bsc#1271117).
  • CVE-2026-59923: HTMLRenderer.safe_url() does not block percent-encoded javascript URIs and allows for XSS (bsc#1271119).
  • CVE-2026-59924: improper processing of user-supplied include paths in Include.parse() can lead to path traversal and arbitrary file reads (bsc#1271121).
  • CVE-2026-59925: quadratic-time parsing on long runs of some emphasis pairs in inline_parser can lead to DoS (bsc#1271125).
  • CVE-2026-59926: improper escaping in render_admonition() can lead to atribute injection and XSS (bsc#1271127).
  • CVE-2026-59927: uncontrolled recursion when processing two markdown files that include each other can lead to a DoS (bsc#1271128).
  • CVE-2026-59928: quadratic-time parsing on long lists of repeated reference-link definitions in block_parser can lead to DoS (bsc#1271131).
  • CVE-2026-59929: HARMFUL_PROTOCOLS list misses legacy and chained schemes and allow arbitrary script execution in user agents (bsc#1271132).
  • CVE-2026-59930: the toc plugin and TableOfContents directive generate heading IDs with predictable values and allow for collisions with attacker-controlled id="toc_N" content (bsc#1271082).
References

Affected packages

SUSE:Linux Enterprise Server 16.0 / python-mistune

Package

Name
python-mistune
Purl
pkg:rpm/suse/python-mistune&distro=SUSE%20Linux%20Enterprise%20Server%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.3-160000.5.1

Ecosystem specific

{
    "binaries": [
        {
            "python313-mistune": "3.1.3-160000.5.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22655-1.json"

SUSE:Linux Enterprise Server for SAP applications 16.0 / python-mistune

Package

Name
python-mistune
Purl
pkg:rpm/suse/python-mistune&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.3-160000.5.1

Ecosystem specific

{
    "binaries": [
        {
            "python313-mistune": "3.1.3-160000.5.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22655-1.json"