MGASA-2026-0377
Advisory lineage Upstream: 2 Downstream: 0
Upstream
Published: 05 Sept 2026, 04:35
Last modified:05 Sept 2026, 04:45
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
05 Sept 2026, 04:35
Published
Vulnerability first disclosed
05 Sept 2026, 04:45
Last Modified
Vulnerability information updated
Description
Updated python-linkify-it-py package fixes security vulnerabilities LinkifyIt.match() was quadratic on untrusted input when linkify is enabled (GHSA-8m2q-wq3r-6hq8). Fix quadratic complexity in LinkifyIt.match(), port of linkify-it 5.0.1 and 5.0.2 (upstream CVE-2026-48801, CVE-2026-59887) (#82) Match validators at a position instead of slicing the tail, needed because Python 3.10 does not optimize the ^ anchor (#82) Allow ; in the email name, matching linkify-it. Behavior change: a;b@example.com is now linkified (#82)
Affected Systems
- mageia•python-linkify-it-py
< 2.1.1-1.mga10