Skip to content

Bump pymdown-extensions to 11.0.1 (doc dependency) - #991

Open
katsugtgz wants to merge 1 commit into
python-pendulum:masterfrom
katsugtgz:fix/pymdown-extensions-cve-2026-67422
Open

Bump pymdown-extensions to 11.0.1 (doc dependency)#991
katsugtgz wants to merge 1 commit into
python-pendulum:masterfrom
katsugtgz:fix/pymdown-extensions-cve-2026-67422

Conversation

@katsugtgz

Copy link
Copy Markdown

Bumps pymdown-extensions from 10.12 to 11.0.1 in the doc dependency group.

Cleared advisories:

  • GHSA-gm37-52c6-37mw (CVE-2026-67422) — ReDoS in caret/tilde/betterem/magiclink processors
  • PYSEC-2026-3654 — exponential-backtracking ReDoS
  • PYSEC-2026-3609 — path traversal in b64 extension
  • PYSEC-2026-2999 — sibling-prefix path traversal bypass in snippets
  • PYSEC-2026-1825 — ReDoS in Figure Capture extension

Remaining advisories (unrelated packages, not addressed in this PR):

  • PYSEC-2026-2132 (click), PYSEC-2026-1374/1375 (filelock), PYSEC-2026-1471/1472/1475 (jinja2), PYSEC-2026-89 (markdown), PYSEC-2026-2987 (pygments), PYSEC-2026-1845 (pytest), PYSEC-2026-2009 (virtualenv)

Changes: pyproject.toml upper bound >=6,<11>=6,<12, poetry.lock updated to 11.0.1 with hashes from PyPI. This is a docs/build dependency only.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant