{"id":"SUSE-SU-2026:22655-1","summary":"Security update for python-mistune","details":"This update for python-mistune fixes the following issues\n\n- CVE-2026-59922: quadratic-time parsing on long runs of some markers in `formatting.py` can lead to DoS (bsc#1271117).\n- CVE-2026-59923: `HTMLRenderer.safe_url()` does not block percent-encoded javascript URIs and allows for XSS\n  (bsc#1271119).\n- CVE-2026-59924: improper processing of user-supplied include paths in `Include.parse()` can lead to path traversal\n  and arbitrary file reads (bsc#1271121).\n- CVE-2026-59925: quadratic-time parsing on long runs of some emphasis pairs in `inline_parser` can lead to DoS\n  (bsc#1271125).\n- CVE-2026-59926: improper escaping in `render_admonition()` can lead to atribute injection and XSS (bsc#1271127).\n- CVE-2026-59927: uncontrolled recursion when processing two markdown files that include each other can lead to a DoS\n   (bsc#1271128).\n- CVE-2026-59928: quadratic-time parsing on long lists of repeated reference-link definitions in `block_parser` can\n  lead to DoS (bsc#1271131).\n- CVE-2026-59929: HARMFUL_PROTOCOLS list misses legacy and chained schemes and allow arbitrary script execution in\n  user agents (bsc#1271132).\n- CVE-2026-59930: the `toc` plugin and `TableOfContents` directive generate heading IDs with predictable values and\n  allow for collisions with attacker-controlled `id=\"toc_N\"` content (bsc#1271082).\n","modified":"2026-07-17T18:24:04.909442220Z","published":"2026-07-14T10:37:38Z","related":["CVE-2026-44896","CVE-2026-59922","CVE-2026-59923","CVE-2026-59924","CVE-2026-59925","CVE-2026-59926","CVE-2026-59927","CVE-2026-59928","CVE-2026-59929","CVE-2026-59930"],"upstream":["CVE-2026-44896","CVE-2026-59922","CVE-2026-59923","CVE-2026-59924","CVE-2026-59925","CVE-2026-59926","CVE-2026-59927","CVE-2026-59928","CVE-2026-59929","CVE-2026-59930"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622655-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271082"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271117"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271119"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271121"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271125"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271127"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271128"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271131"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271132"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44896"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59922"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59924"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59925"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59926"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59927"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59928"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59929"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59930"}],"affected":[{"package":{"name":"python-mistune","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/python-mistune&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"python313-mistune":"3.1.3-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22655-1.json"}},{"package":{"name":"python-mistune","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/python-mistune&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.3-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"python313-mistune":"3.1.3-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22655-1.json"}}],"schema_version":"1.7.5"}