


Perceptive Security
SOC/SIEM Consultancy

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character cau…
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 18:04:27
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
CVE-2026-59922 affects Mistune, a Python Markdown parser, in versions prior to 3.3.0. The vulnerability exists in src/mistune/plugins/formatting.py where the strikethrough, mark, or insert plugins scan for matching markers (tilde, equals-sign, or caret) from each possible start position. A specially crafted input using closed marker pairs around a character triggers quadratic computational work, leading to CPU exhaustion and denial of service. This is a ReDoS-style algorithmic complexity vulnerability. The issue was fixed in Mistune version 3.3.0. Users are advised to upgrade immediately to mitigate the risk of service disruption through maliciously crafted Markdown input.
Technical details
Mitigation steps:
Affected products:
Mistune Python Markdown Parser (versions prior to 3.3.0)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59922
https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7
https://github.com/lepture/mistune/releases/tag/v3.3.0
https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
