Skip to content

[GHSA-v7cf-c9rm-wm3j] Add CVE-2026-9769 and justhtml 1.10.0 fix commits - #9192

Open
SebTardif wants to merge 1 commit into
github:SebTardif/advisory-improvement-9192from
SebTardif:sebtardif-GHSA-v7cf-c9rm-wm3j
Open

[GHSA-v7cf-c9rm-wm3j] Add CVE-2026-9769 and justhtml 1.10.0 fix commits#9192
SebTardif wants to merge 1 commit into
github:SebTardif/advisory-improvement-9192from
SebTardif:sebtardif-GHSA-v7cf-c9rm-wm3j

Conversation

@SebTardif

Copy link
Copy Markdown

Summary

Add the public CVE alias and the justhtml 1.10.0 security fix commits to GHSA-v7cf-c9rm-wm3j.

The advisory already has the correct PyPI package and fixed: 1.10.0 range. It does not list CVE-2026-9769, and its only code reference is the v1.10.0 release tag.

Evidence

CVE-2026-9769 is the same issue. The CNA record title is "justhtml before 1.10.0 Denial of Service via deeply nested HTML", the affected range is < 1.10.0, and the first reference is this GHSA:

The v1.10.0 release commit (5095a058) only bumps pyproject.toml. The security work is the three commits immediately before it:

PyPI has both 1.9.1 and 1.10.0.

Change

One file: advisories/github-reviewed/2026/03/GHSA-v7cf-c9rm-wm3j/GHSA-v7cf-c9rm-wm3j.json

  • aliases: add CVE-2026-9769
  • references: add the three commit URLs (same WEB type used on other reviewed advisories)
  • modified: 2026-08-23T16:37:15Z

Copilot AI balanced review requested due to automatic review settings August 23, 2026 16:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions
github-actions Bot changed the base branch from main to SebTardif/advisory-improvement-9192 August 23, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants