MGASA-2026-0377
Dashboard / Vulnerabilities / MGASA-2026-0377
MGASA-2026-0377
Summary: Updated python-linkify-it-py package fixes security vulnerabilities
Details: LinkifyIt.match() was quadratic on untrusted input when linkify is enabled (GHSA-8m2q-wq3r-6hq8). Fix quadratic complexity in LinkifyIt.match(), port of linkify-it 5.0.1 and 5.0.2 (upstream CVE-2026-48801, CVE-2026-59887) (#82) Match validators at a position instead of slicing the tail, needed because Python 3.10 does not optimize the ^ anchor (#82) Allow ; in the email name, matching linkify-it. Behavior change: a;[email protected] is now linkified (#82)
References: https://advisories.mageia.org/MGASA-2026-0377.html, https://bugs.mageia.org/show_bug.cgi?id=36247, https://lists.fedoraproject.org/archives/list/[email protected]/message/DZROSWVUL5NSOK5V2O56ZMD6SRN2KV7V/
Affected packages
Package
Name: python-linkify-it-py
Purl: pkg:rpm/mageia/python-linkify-it-py?arch=source&distro=mageia-10
Affected ranges
Type: ECOSYSTEM
Events:
