openSUSE-SU-2026:21339-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21339-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21339-1
Upstream
Related
Published
2026-07-14T10:41:18Z
Modified
2026-07-15T18:24:25.827620397Z
Summary
Security update for python-mistune
Details

This update for python-mistune fixes the following issues

  • CVE-2026-59922: quadratic-time parsing on long runs of some markers in formatting.py can lead to DoS (bsc#1271117).
  • CVE-2026-59923: HTMLRenderer.safe_url() does not block percent-encoded javascript URIs and allows for XSS (bsc#1271119).
  • CVE-2026-59924: improper processing of user-supplied include paths in Include.parse() can lead to path traversal and arbitrary file reads (bsc#1271121).
  • CVE-2026-59925: quadratic-time parsing on long runs of some emphasis pairs in inline_parser can lead to DoS (bsc#1271125).
  • CVE-2026-59926: improper escaping in render_admonition() can lead to atribute injection and XSS (bsc#1271127).
  • CVE-2026-59927: uncontrolled recursion when processing two markdown files that include each other can lead to a DoS (bsc#1271128).
  • CVE-2026-59928: quadratic-time parsing on long lists of repeated reference-link definitions in block_parser can lead to DoS (bsc#1271131).
  • CVE-2026-59929: HARMFUL_PROTOCOLS list misses legacy and chained schemes and allow arbitrary script execution in user agents (bsc#1271132).
  • CVE-2026-59930: the toc plugin and TableOfContents directive generate heading IDs with predictable values and allow for collisions with attacker-controlled id="toc_N" content (bsc#1271082).
References

Affected packages

openSUSE:Leap 16.0 / python-mistune

Package

Name
python-mistune
Purl
pkg:rpm/opensuse/python-mistune&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.3-160000.5.1

Ecosystem specific

{
    "binaries": [
        {
            "python313-mistune": "3.1.3-160000.5.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21339-1.json"