top of page
perceptive_background_267k.jpg

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character cau…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 18:04:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

CVE-2026-59922 affects Mistune, a Python Markdown parser, in versions prior to 3.3.0. The vulnerability exists in src/mistune/plugins/formatting.py where the strikethrough, mark, or insert plugins scan for matching markers (tilde, equals-sign, or caret) from each possible start position. A specially crafted input using closed marker pairs around a character triggers quadratic computational work, leading to CPU exhaustion and denial of service. This is a ReDoS-style algorithmic complexity vulnerability. The issue was fixed in Mistune version 3.3.0. Users are advised to upgrade immediately to mitigate the risk of service disruption through maliciously crafted Markdown input.

Technical details

Mitigation steps:

Affected products:

Mistune Python Markdown Parser (versions prior to 3.3.0)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page