Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each possible start position, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.
References
| Link | Resource |
|---|---|
| https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7 | Patch |
| https://github.com/lepture/mistune/releases/tag/v3.3.0 | Release Notes |
| https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq | Exploit Vendor Advisory |
| https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq | Exploit Vendor Advisory |
Configurations
History
09 Jul 2026, 19:36
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mistune Project
Mistune Project mistune |
|
| References | () https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7 - Patch | |
| References | () https://github.com/lepture/mistune/releases/tag/v3.3.0 - Release Notes | |
| References | () https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:mistune_project:mistune:*:*:*:*:*:*:*:* |
09 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq - |
08 Jul 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-08 17:17
Updated : 2026-07-09 19:36
NVD link : CVE-2026-59922
Mitre link : CVE-2026-59922
CVE.ORG link : CVE-2026-59922
JSON object : View
Products Affected
mistune_project
- mistune
