Skip to content

[AUTOPATCHER-CORE] Upgrade python-mistune to 3.2.1 CVE-2026-33079 [HIGH]#17131

Open
CBL-Mariner-Bot wants to merge 2 commits into
fasttrack/3.0from
cblmargh/python-mistune-upgrade-to-3.2.1-fasttrack/3.0
Open

[AUTOPATCHER-CORE] Upgrade python-mistune to 3.2.1 CVE-2026-33079 [HIGH]#17131
CBL-Mariner-Bot wants to merge 2 commits into
fasttrack/3.0from
cblmargh/python-mistune-upgrade-to-3.2.1-fasttrack/3.0

Conversation

@CBL-Mariner-Bot
Copy link
Copy Markdown
Collaborator

@CBL-Mariner-Bot CBL-Mariner-Bot commented May 11, 2026

[AUTOPATCHER-CORE] Upgrade python-mistune to 3.2.1 CVE-2026-33079
Upgrade pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1115023&view=results
Buddy Build

@Kanishk-Bansal
Copy link
Copy Markdown
Contributor

Kanishk-Bansal commented May 11, 2026

No breaking changes are documented in the changelog between v3.0.2 and v3.2.1 at lepture/mistune@v3.0.2...v3.2.1.

All entries are bug fixes, security/escaping improvements, and additive changes (no "Breaking change" markers, which the maintainer did use explicitly for earlier 3.0.0 release candidates).

Highlights across the range (v3.1.0 → v3.2.1):

  • v3.2.1 (May 2026) — Mostly security/escaping fixes:
    • Escape link in render_toc_ul, escape text in math plugin, escape heading ID, escape class attribute for admonition/image directives
    • Fix LINK_TITLE_RE to prevent DoS
    • Remove double-encoding of image alt text
    • Fix width/height attribute for image directive
  • v3.2.0 — Python 3.14 support; footnotes plugin fixes; ref links in TOC fix
  • v3.1.4 — Fenced directive break rule in list parser; unicode whitespace fix in ATX headings
  • v3.1.3 — Python 3.12/3.13 support
  • v3.1.2footnotes plugin fix for AST renderer
  • v3.1.1render_toc_ul empty iterable fix; ruby plugin regex/HTML fixes
  • v3.1.0 — Only HTML-escape URLs when rendering to HTML; block_quote prefix on empty lines

@Kanishk-Bansal Kanishk-Bansal changed the title [AUTOPATCHER-CORE] Upgrade python-mistune to 3.2.1 CVE-2026-33079 [AUTOPATCHER-CORE] Upgrade python-mistune to 3.2.1 CVE-2026-33079 May 11, 2026
@Kanishk-Bansal Kanishk-Bansal changed the title [AUTOPATCHER-CORE] Upgrade python-mistune to 3.2.1 CVE-2026-33079 [AUTOPATCHER-CORE] Upgrade python-mistune to 3.2.1 CVE-2026-33079 [HIGH] May 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants