{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21176-1","published":"2026-06-30T07:49:32Z","modified":"2026-07-02T18:24:18.559035843Z","related":["CVE-2026-13311","CVE-2026-53550"],"upstream":["CVE-2026-13311","CVE-2026-53550"],"summary":"Security update for python-pytest-html","details":"This update for python-pytest-html fixes the following issues:\n\nChanges in python-pytest-html:\n\n- Revendor updating shell-quote and js-yaml deps:\n  - CVE-2026-13311: shell-quote: inefficient input parsing can lead to a\n    denial of service (bsc#1269361)\n  - CVE-2026-53550: js-yaml: quadratic complexity when processing a\n    crafted YAML document can lead to CPU exhaustion (bsc#1268818)\n","affected":[{"package":{"name":"python-pytest-html","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/python-pytest-html&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1-bp160.3.1"}]}],"ecosystem_specific":{"binaries":[{"python313-pytest-html":"4.1.1-bp160.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21176-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268818"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269361"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13311"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53550"}]}