CVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id=”toc_N”` content Posted on July 11, 2026 by Syndicated News — No Comments ↓ Information published. Continue reading CVE-2026-59930 Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id=”toc_N”` content→
CVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert) Posted on July 11, 2026 by Syndicated News — No Comments ↓ Information published. Continue reading CVE-2026-59922 Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)→
CVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs Posted on July 11, 2026 by Syndicated News — No Comments ↓ Information published. Continue reading CVE-2026-59925 inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs→
CVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directive Posted on July 11, 2026 by Syndicated News — No Comments ↓ Information published. Continue reading CVE-2026-59926 Mistune: XSS via unescaped class option in Admonition directive→
CVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions Posted on July 11, 2026 by Syndicated News — No Comments ↓ Information published. Continue reading CVE-2026-59928 Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions→
CVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment Posted on July 11, 2026 by Syndicated News — No Comments ↓ Information published. Continue reading CVE-2026-14740 DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment→
CVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile Posted on July 11, 2026 by Syndicated News — No Comments ↓ Information published. Continue reading CVE-2026-14380 DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile→
CVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders Posted on July 11, 2026 by Syndicated News — No Comments ↓ Information published. Continue reading CVE-2026-14739 DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders→