High severity7.5NVD Advisory· Published Jul 25, 2022· Updated Jun 17, 2026
CVE-2022-34749
CVE-2022-34749
Description
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mistunePyPI | >= 2.0.0a1, < 2.0.3 | 2.0.3 |
Affected products
5- mistune/mistunedescription
- osv-coords2 versions
< 3.1.0-1.1+ 1 more
- (no CPE)range: < 3.1.0-1.1
- (no CPE)range: >= 2.0.0a1, < 2.0.3
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- github.com/lepture/mistune/commit/a6d43215132fe4f3d93f8d7e90ba83b16a0838b2nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-fw3v-x4f2-v673ghsaADVISORY
- github.com/lepture/mistune/releasesnvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-34749ghsaADVISORY
- github.com/lepture/mistune/commit/ca1e7b506850f4e488823fc7338b49a8f9852718ghsaWEB
- github.com/lepture/mistune/issues/314ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2022-237.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/TQHXITQ2DSBYOILKHXBSBB7PFBPZHF63ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQHXITQ2DSBYOILKHXBSBB7PFBPZHF63/nvd
News mentions
0No linked articles in our index yet.