Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59927

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.3

Описание

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionError, and crash the rendering request. This issue is fixed in version 3.3.0.

A flaw was found in Mistune, a Python Markdown parser. The Include directive in Mistune's src/mistune/directives/include.py does not properly detect indirect cycles when two Markdown files include each other. This oversight allows for unbounded recursion, which can lead to a RecursionError and crash the rendering request, resulting in a Denial of Service (DoS) for the application using the parser.

Отчет

This flaw in the Mistune Include directive can cause a denial of service when an application explicitly enables the Include plugin and renders user-controlled Markdown files from disk. Exploitation requires an attacker to place at least two coordinated Markdown files on the include search path; default Mistune configurations that parse inline strings without the Include plugin are not affected.

Меры по смягчению последствий

To mitigate this issue, Red Hat recommends avoiding the processing of untrusted Markdown content that may contain recursively linked include directives. Users should ensure that any Markdown files processed by applications utilizing Mistune are from trusted sources or are thoroughly sanitized to prevent indirect cyclic inclusions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9Under investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9Under investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9Under investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9Under investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9Under investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9Under investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9Under investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch210-py312-rhel9Under investigation
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch291-py312-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2498154mistune: Mistune: Denial of Service via unbounded recursion in Markdown include directive

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
26 дней назад

(Mistune is a Python Markdown parser with renderers and plugins. Prior ...)

CVSS3: 5.3
nvd
26 дней назад

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionError, and crash the rendering request. This issue is fixed in version 3.3.0.

CVSS3: 5.3
debian
26 дней назад

Mistune is a Python Markdown parser with renderers and plugins. Prior ...

5.3 Medium

CVSS3