VYPR

rpm package

opensuse/python-pytest-html&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/python-pytest-html&distro=openSUSE%20Leap%2016.0

Vulnerabilities (3)

  • CVE-2026-13149HigJun 30, 2026
    affected < 4.1.1-bp160.4.1fixed 4.1.1-bp160.4.1

    brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign

  • CVE-2026-13311HigJun 25, 2026
    affected < 4.1.1-bp160.3.1fixed 4.1.1-bp160.3.1

    shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacke

  • CVE-2026-53550MedJun 22, 2026
    affected < 4.1.1-bp160.3.1fixed 4.1.1-bp160.3.1

    js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior rel