High severity7.5OSV Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-59922
CVE-2026-59922
Description
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each possible start position, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mistunePyPI | < 3.3.0 | 3.3.0 |
Affected products
4Patches
Vulnerability mechanics
References
6- github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7nvdPatchWEB
- github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmqnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-c8j7-8cv4-2xmqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59922ghsaADVISORY
- github.com/lepture/mistune/releases/tag/v3.3.0nvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2210.yamlghsaWEB
News mentions
2- Mistune Project: Nine Vulnerabilities Including DoS and XSS Disclosed TogetherVypr Intelligence · Jul 9, 2026
- Authlib Mistune: Nine Vulnerabilities Including DoS and XSS Disclosed TogetherVypr Intelligence · Jul 9, 2026