shield
Security update for python-mistune
SUSE-SLES-16.0-1243
This update for python-mistune fixes the following issues - CVE-2026-59922: quadratic-time parsing on long runs of some markers in `formatting.py` can lead to DoS (bsc#1271117). - CVE-2026-59923: `HTMLRenderer.safe_url()` does not block percent-encoded javascript URIs and allows for XSS (bsc#1271119). - CVE-2026-59924: improper processing of user-supplied include paths in `Include.parse()` can lead to path traversal and arbitrary file reads (bsc#1271121). - CVE-2026-59925: quadratic-time parsing on long runs of some emphasis pairs in `inline_parser` can lead to DoS (bsc#1271125). - CVE-2026-59926: improper escaping in `render_admonition()` can lead to atribute injection and XSS (bsc#1271127). - CVE-2026-59927: uncontrolled recursion when processing two markdown files that include each other can lead to a DoS (bsc#1271128). - CVE-2026-59928: quadratic-time parsing on long lists of repeated reference-link definitions in `block_parser` can lead to DoS (bsc#1271131). - CVE-2026-59929: HARMFUL_PROTOCOLS list misses legacy and chained schemes and allow arbitrary script execution in user agents (bsc#1271132). - CVE-2026-59930: the `toc` plugin and `TableOfContents` directive generate heading IDs with predictable values and allow for collisions with attacker-controlled `id="toc_N"` content (bsc#1271082).
-
Release DateJul 14 2026
-
ReferencesBugzilla: 1271082, 1271117, 1271119, 1271121, 1271125, 1271127, 1271128, 1271131, 1271132
CVEs: CVE-2026-44896, CVE-2026-59922, CVE-2026-59923, CVE-2026-59924, CVE-2026-59925, CVE-2026-59926, CVE-2026-59927, CVE-2026-59928, CVE-2026-59929, CVE-2026-59930 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64
-
Packages
SUSE Linux Enterprise Server 16.0 ppc64le
-
Packages
SUSE Linux Enterprise Server 16.0 aarch64
-
Packages
SUSE Linux Enterprise Server 16.0 s390x
-
Packages
SUSE Linux Enterprise Server 16.0 x86_64
-
Packages
SUSE Linux Enterprise Server for SAP applications 16.0 ppc64le
-
Packages