Explore top 10 tips to secure your open-source projects now. Read More
×
Security update. Publication date: 15 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0254.html Type: security Affected Mageia releases: 10 CVE: CVE-2026-44898, CVE-2026-49851 Description: The updated python-mistune package fixes two security vulnerablities: Prior to 3.2.1, render_toc_ul() builds a table-of-contents tree from a list of (level, id, text) tuples. Both the id value (used as href="# ") and the text value (used as the visible link label) are inserted into tags via a plain Python format string — with no HTML escaping applied to either value. When heading IDs are derived from user-supplied heading text (the standard use-case for readable slug anchors), an attacker can craft a heading whose text breaks out of the href="#..." attribute context, injecting arbitrary HTML tags including blocks directly into the rendered TOC. (CVE-44898) Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repeatedly scans the input using a regex search inside a loop. Each iteration re-scans a large portion of the remaining string, resulting in quadratic-time behavior. An attacker-controlled Markdown input can therefore trigger excessive CPU usage with a very small payload. (CVE-2026-49851) References: - https://bugs.mageia.org/show_bug.cgi?id=35773 - https://lists.opensuse.org/archives/list/
Template-Toolkit could allow arbitrary HTML and JavaScript to be injected into generated output.. ========================================================================== Ubuntu Security Notice USN-8377-1 June 03, 2026 libtemplate-perl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Template-Toolkit could allow arbitrary HTML and JavaScript to be injected into generated output. Software Description: - libtemplate-perl: template processing system in Perl Details: It was discovered that Template-Toolkit did not properly escape single quotes in the html_filter function of Template::Plugin::HTML. An attacker could possibly use this issue to inject arbitrary HTML and JavaScript into generated output. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libtemplate-perl 3.102-1ubuntu0.1 Ubuntu 25.10 libtemplate-perl 2.27-1ubuntu0.25.10.1 Ubuntu 24.04 LTS libtemplate-perl 2.27-1ubuntu0.24.04.1 Ubuntu 22.04 LTS libtemplate-perl 2.27-1ubuntu0.22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8377-1 CVE-2026-5090 Package Information: https://launchpad.net/ubuntu/+source/libtemplate-perl/3.102-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libtemplate-perl/2.27-1ubuntu0.25.10.1 https://launchpad.net/ubuntu/+source/libtemplate-perl/2.27-1ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/libtemplate-perl/2.27-1ubuntu0.22.04.1 . Template-Toolkit in Ubuntu can allow arbitrary HTML and JavaScript injection, potentially compromising system integrity.. Ubuntu libtemplate-perl security fixed issues. . Severity: Critical. LinuxSecurity.com Team
Template-Toolkit could allow arbitrary HTML and JavaScript to be injected into generated output.. ========================================================================== Ubuntu Security Notice USN-8377-1 June 03, 2026 libtemplate-perl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Template-Toolkit could allow arbitrary HTML and JavaScript to be injected into generated output. Software Description: - libtemplate-perl: template processing system in Perl Details: It was discovered that Template-Toolkit did not properly escape single quotes in the html_filter function of Template::Plugin::HTML. An attacker could possibly use this issue to inject arbitrary HTML and JavaScript into generated output. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libtemplate-perl 3.102-1ubuntu0.1 Ubuntu 25.10 libtemplate-perl 2.27-1ubuntu0.25.10.1 Ubuntu 24.04 LTS libtemplate-perl 2.27-1ubuntu0.24.04.1 Ubuntu 22.04 LTS libtemplate-perl 2.27-1ubuntu0.22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8377-1 CVE-2026-5090 Package Information: https://launchpad.net/ubuntu/+source/libtemplate-perl/3.102-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libtemplate-perl/2.27-1ubuntu0.25.10.1 https://launchpad.net/ubuntu/+source/libtemplate-perl/2.27-1ubuntu0.24.04.1 https://launchpad.net/ubuntu/+source/libtemplate-perl/2.27-1ubuntu0.22.04.1 . Template-Toolkit in Ubuntu allows HTML/JavaScript injections. Update recommended to avoid security risks and vulnerabilities.. HTML injection, JavaScript security, Ubuntu Template-Toolkit, system update, libtemplate-perl. . Severity: Important.LinuxSecurity.com Team
Multiple vulnerabilities were discovered in log4cxx, a logging library for C++ that is compatible with the JAVA log4j framework. CVE-2025-54812 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4322-1
Multiple vulnerabilities were discovered in nextcloud-desktop, nextcloud folder synchronization tool. CVE-2022-39331 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4303-1
* bsc#1218722 * bsc#1223980 Cross-References: * CVE-2024-22195 . # Security update for python-Jinja2 Announcement ID: SUSE-SU-2024:1864-1 Rating: moderate References: * bsc#1218722 * bsc#1223980 Cross-References: * CVE-2024-22195 * CVE-2024-34064 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-34064 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * Python 3 Module 15-SP5 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-Jinja2 fixes the following issues: * Fixed HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-34064, bsc#1223980, CVE-2024-22195, bsc#1218722) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-1864=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1864=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-1864=1 * Python 3 Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Python3-15-SP5-2024-1864=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2024-1864=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) *python311-Jinja2-3.1.2-150400.12.6.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python311-Jinja2-3.1.2-150400.12.6.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python311-Jinja2-3.1.2-150400.12.6.1 * Python 3 Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python311-Jinja2-3.1.2-150400.12.6.1 * Python 3 Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python311-Jinja2-3.1.2-150400.12.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2024-34064.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1223980 . Stay informed about moderate vulnerabilities in Jinja2 templating engine for Python and ensure your apps use the latest secure version for risk mitigation. SUSE Updates, Python Security, Linux Patch Management. . LinuxSecurity.com Team
* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671 . # Security update for python3-Twisted Announcement ID: SUSE-SU-2024:2860-1 Rating: important References: * bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671 * CVE-2024-41810 CVSS scores: * CVE-2024-41671 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2024-41671 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2024-41810 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2024-41810 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Server Applications Module 15-SP5 * Server Applications Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for python3-Twisted fixes the following issues: * CVE-2024-41671: Fixed HTTP pipelined requests processed out of order in twisted.web (bsc#1228549) * CVE-2024-41810: Fixed reflected XSS via HTML Injection in Redirect Response (bsc#1228552) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methodslike YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-2860=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-2860=1 * Server Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP5-2024-2860=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-2860=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-2860=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-2860=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-2860=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-2860=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-2860=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-2860=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-2860=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python-Twisted-doc-22.2.0-150400.21.1 * python3-Twisted-22.2.0-150400.21.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python3-Twisted-22.2.0-150400.21.1 * Server Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-Twisted-22.2.0-150400.21.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python3-Twisted-22.2.0-150400.21.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python3-Twisted-22.2.0-150400.21.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4(aarch64 x86_64) * python3-Twisted-22.2.0-150400.21.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * python3-Twisted-22.2.0-150400.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python3-Twisted-22.2.0-150400.21.1 * SUSE Manager Proxy 4.3 (x86_64) * python3-Twisted-22.2.0-150400.21.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * python3-Twisted-22.2.0-150400.21.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * python3-Twisted-22.2.0-150400.21.1 ## References: * https://www.suse.com/security/cve/CVE-2024-41671.html * https://www.suse.com/security/cve/CVE-2024-41810.html * https://bugzilla.suse.com/show_bug.cgi?id=1228549 * https://bugzilla.suse.com/show_bug.cgi?id=1228552 . An update for python3-Twisted addresses various vulnerabilities with high severity impacting SUSE offerings.. Security Update, Python3 Twisted, openSUSE Release, Critical Issues. . Severity: Important. LinuxSecurity.com Team
* bsc#1218722 * bsc#1223980 Cross-References: * CVE-2024-22195 . # Security update for python-Jinja2 Announcement ID: SUSE-SU-2024:1863-2 Rating: moderate References: * bsc#1218722 * bsc#1223980 Cross-References: * CVE-2024-22195 * CVE-2024-34064 CVSS scores: * CVE-2024-22195 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-22195 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-34064 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-Jinja2 fixes the following issues: * Fixed HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-34064, bsc#1223980, CVE-2024-22195, bsc#1218722) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1863=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-Jinja2-2.10.1-150000.3.13.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22195.html * https://www.suse.com/security/cve/CVE-2024-34064.html * https://bugzilla.suse.com/show_bug.cgi?id=1218722 * https://bugzilla.suse.com/show_bug.cgi?id=1223980 . An update for python-Jinja2 is now available addressing security concerns regarding HTML attribute injection vulnerabilities on SUSE systems.. SUSE Linux, python Jinja2 Update, Security Advisories, Software Patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.