Medium severity5.3OSV Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-59927
CVE-2026-59927
Description
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionError, and crash the rendering request. This issue is fixed in version 3.3.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mistunePyPI | < 3.3.0 | 3.3.0 |
Affected products
4Patches
Vulnerability mechanics
References
6- github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993nvdPatchWEB
- github.com/lepture/mistune/security/advisories/GHSA-8mpj-m6qm-5qr8nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-8mpj-m6qm-5qr8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59927ghsaADVISORY
- github.com/lepture/mistune/releases/tag/v3.3.0nvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2026-2215.yamlghsaWEB
News mentions
2- Mistune Project: Nine Vulnerabilities Including DoS and XSS Disclosed TogetherVypr Intelligence · Jul 9, 2026
- Authlib Mistune: Nine Vulnerabilities Including DoS and XSS Disclosed TogetherVypr Intelligence · Jul 9, 2026