{"id":"openSUSE-SU-2026:21339-1","summary":"Security update for python-mistune","details":"This update for python-mistune fixes the following issues\n\n- CVE-2026-59922: quadratic-time parsing on long runs of some markers in `formatting.py` can lead to DoS (bsc#1271117).\n- CVE-2026-59923: `HTMLRenderer.safe_url()` does not block percent-encoded javascript URIs and allows for XSS\n  (bsc#1271119).\n- CVE-2026-59924: improper processing of user-supplied include paths in `Include.parse()` can lead to path traversal\n  and arbitrary file reads (bsc#1271121).\n- CVE-2026-59925: quadratic-time parsing on long runs of some emphasis pairs in `inline_parser` can lead to DoS\n  (bsc#1271125).\n- CVE-2026-59926: improper escaping in `render_admonition()` can lead to atribute injection and XSS (bsc#1271127).\n- CVE-2026-59927: uncontrolled recursion when processing two markdown files that include each other can lead to a DoS\n   (bsc#1271128).\n- CVE-2026-59928: quadratic-time parsing on long lists of repeated reference-link definitions in `block_parser` can\n  lead to DoS (bsc#1271131).\n- CVE-2026-59929: HARMFUL_PROTOCOLS list misses legacy and chained schemes and allow arbitrary script execution in\n  user agents (bsc#1271132).\n- CVE-2026-59930: the `toc` plugin and `TableOfContents` directive generate heading IDs with predictable values and\n  allow for collisions with attacker-controlled `id=\"toc_N\"` content (bsc#1271082).\n","modified":"2026-07-15T10:00:11.548963212Z","published":"2026-07-14T10:41:18Z","related":["CVE-2026-44896","CVE-2026-59922","CVE-2026-59923","CVE-2026-59924","CVE-2026-59925","CVE-2026-59926","CVE-2026-59927","CVE-2026-59928","CVE-2026-59929","CVE-2026-59930"],"upstream":["CVE-2026-44896","CVE-2026-59922","CVE-2026-59923","CVE-2026-59924","CVE-2026-59925","CVE-2026-59926","CVE-2026-59927","CVE-2026-59928","CVE-2026-59929","CVE-2026-59930"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271082"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271117"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271119"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271121"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271125"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271127"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271128"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271131"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271132"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44896"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59922"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59924"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59925"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59926"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59927"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59928"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59929"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59930"}],"affected":[{"package":{"name":"python-mistune","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/python-mistune&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"python313-mistune":"3.1.3-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21339-1.json"}}],"schema_version":"1.7.5"}