Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76098

Опубликовано: 24 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing process. This issue is fixed in version 3.3.3

A flaw was found in Mistune, a Python Markdown parser. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted Markdown input. The excessive use of emphasis markers, such as consecutive asterisks, creates deeply nested tokens during HTML rendering. This process can exceed Python's recursion limit, causing the parsing application to crash.

Отчет

This flaw in the Mistune Python Markdown parser can lead to a denial of service in Red Hat OpenShift AI and Migration Toolkit for Applications. By submitting specially crafted Markdown input with excessive emphasis markers, an attacker can trigger deep recursion, causing the parsing process to crash and disrupt service availability.

Меры по смягчению последствий

Mitigation for this issue involves restricting the processing of untrusted Markdown content by applications utilizing the vulnerable Mistune library. If applications are exposed to untrusted input, implement input sanitization to prevent deeply nested emphasis structures that could trigger the denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-feature-server-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch210-py312-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2523100mistune: Mistune: Denial of Service via excessive emphasis markers in Markdown

EPSS

Процентиль: 20%
0.00278
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing process. This issue is fixed in version 3.3.3

CVSS3: 7.5
nvd
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing process. This issue is fixed in version 3.3.3

msrc
22 дня назад

Mistune has Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

CVSS3: 7.5
debian
24 дня назад

Mistune is a Python Markdown parser with renderers and plugins. Versio ...

CVSS3: 7.5
github
15 дней назад

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

EPSS

Процентиль: 20%
0.00278
Низкий

7.5 High

CVSS3