Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59925

Опубликовано: 08 июл. 2026
Источник: debian
EPSS Низкий

Описание

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from every potential opening run, allowing denial of service in default Mistune parsing. This issue is fixed in version 3.3.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mistuneunfixedpackage
mistuneno-dsatrixiepackage
mistunenot-affectedbookwormpackage
mistunenot-affectedbullseyepackage

Примечания

  • https://github.com/lepture/mistune/security/advisories/GHSA-4j32-57v6-6g45

  • Fixed by: https://github.com/lepture/mistune/commit/5de41fb8e527004dbc363e047a3c380c9288c74f (v3.3.0)

EPSS

Процентиль: 34%
0.0041
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from every potential opening run, allowing denial of service in default Mistune parsing. This issue is fixed in version 3.3.0.

CVSS3: 6.5
redhat
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from every potential opening run, allowing denial of service in default Mistune parsing. This issue is fixed in version 3.3.0.

CVSS3: 7.5
nvd
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from every potential opening run, allowing denial of service in default Mistune parsing. This issue is fixed in version 3.3.0.

msrc
22 дня назад

inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs

CVSS3: 7.5
github
12 дней назад

Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs

EPSS

Процентиль: 34%
0.0041
Низкий