VYPR

rpm package

opensuse/python-pydata-sphinx-theme&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/python-pydata-sphinx-theme&distro=openSUSE%20Tumbleweed

Vulnerabilities (4)

  • CVE-2026-13676HigJun 29, 2026
    affected < 0.19.0-2.1fixed 0.19.0-2.1

    fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() an

  • CVE-2026-53550MedJun 22, 2026
    affected < 0.19.0-1.1fixed 0.19.0-1.1

    js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior rel

  • CVE-2026-6321HigMay 4, 2026
    affected < 0.17.1-1.1fixed 0.17.1-1.1

    fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalize

  • CVE-2025-5889LowJun 9, 2025
    affected < 0.16.1-1.1fixed 0.16.1-1.1

    A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be l