Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59928

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.

A flaw was found in Mistune, a Python Markdown parser. A remote attacker could exploit this vulnerability by providing a specially crafted Markdown document containing numerous repeated or distinct reference-link definitions. This can lead to excessive processing, causing CPU exhaustion and a denial of service (DoS) for the affected system.

Отчет

A flaw was found in Mistune, a Python Markdown parser. An attacker who can supply Markdown for parsing could exploit this vulnerability by providing a specially crafted document containing numerous repeated or distinct reference-link definitions. This triggers excessive CPU consumption during parsing, which may render affected applications unresponsive and result in a denial of service. Red Hat uses PR:L because delivering the crafted Markdown document document to Mistune will require authenticated access in affected products, platform login/RBAC prevents unauthenticated remote submission in default deployments. The upstream PR:N score assumes any Internet-facing app parsing untrusted Markdown without authentication.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted Markdown documents with affected Red Hat products. Restricting the input sources to trusted content can reduce the risk of a denial of service attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch210-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch291-py312-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2498156mistune: Mistune: Denial of Service via crafted Markdown document with reference-link definitions

EPSS

Процентиль: 34%
0.00413
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.

CVSS3: 7.5
nvd
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.

msrc
22 дня назад

Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

CVSS3: 7.5
debian
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Prior ...

CVSS3: 7.5
github
12 дней назад

Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions

EPSS

Процентиль: 34%
0.00413
Низкий

6.5 Medium

CVSS3