{"id":"openSUSE-SU-2026:20827-1","summary":"Security update for python-mistune","details":"This update for python-mistune fixes the following issues\n\n- CVE-2026-33079: ReDoS in `LINK_TITLE_RE` can lead to denial of service via a crafted Markdown (bsc#1264347).\n- CVE-2026-33441: processing of malformed reference links can lead to excessive resource consumption and denial of\n  service (bsc#1264752).\n- CVE-2026-44708: improper HTML escaping in the math plugin can lead to XSS (bsc#1264751).\n- CVE-2026-44896: improper escaping in `render_figure` can lead to attribute injection and XSS (bsc#1264754).\n- CVE-2026-44897: improper sanitization of user-controlled input in `HTMLRenderer.heading` can lead to XSS\n  (bsc#1264750).\n- CVE-2026-44898: improper sanitization of user-supplied HTML input in `render_toc_ul` can lead to XSS (bsc#1265052).\n- CVE-2026-44899: improper input verification in Image directive plugin and improper escaping in `render_block_image`\n  can lead to CSS injection (bsc#1265053).\n","modified":"2026-05-31T18:24:46.635619375Z","published":"2026-05-28T12:07:59Z","related":["CVE-2026-33079","CVE-2026-33441","CVE-2026-44708","CVE-2026-44896","CVE-2026-44897","CVE-2026-44898","CVE-2026-44899"],"upstream":["CVE-2026-33079","CVE-2026-33441","CVE-2026-44708","CVE-2026-44896","CVE-2026-44897","CVE-2026-44898","CVE-2026-44899"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264347"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264750"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264751"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264752"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264754"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33079"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44708"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44896"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44897"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44898"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44899"}],"schema_version":"1.7.5"}