{"id":"openSUSE-SU-2026:21602-1","summary":"Security update for python-pytest-html","details":"This update for python-pytest-html fixes the following issues:\n\nChanges in python-pytest-html:\n\n- Revendor browserslist to fix the following:\n  * CVE-2026-73088: unguarded for...in loop over untrusted JSON keys in normalizeStats() function leads to prototype pollution and uncaught exceptions (bsc#1275374)\n  * CVE-2026-73089: unbounded in-memory caching of query pairs in browserslist() can lead to DoS via memory exhaustion through a high volume of distinct queries (bsc#1275437)\n","modified":"2026-08-21T18:23:50.412744212Z","published":"2026-08-18T15:53:05Z","related":["CVE-2026-73088","CVE-2026-73089"],"upstream":["CVE-2026-73088","CVE-2026-73089"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275374"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275437"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73088"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73089"}],"affected":[{"package":{"name":"python-pytest-html","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/python-pytest-html&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1-bp160.5.1"}]}],"ecosystem_specific":{"binaries":[{"python313-pytest-html":"4.1.1-bp160.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21602-1.json"}}],"schema_version":"1.9.0"}