CVE-2026-59928
HIGHMistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
Title source: cnaDescription
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/lepture/mistune/security/advisories/GHSA-ffq3-xpv3-j92q
X_Refsource_Misc x_refsource_misc
https://github.com/lepture/mistune/commit/2b04d7ba341c16ac78fe82d3076bdd5c3de87c69
X_Refsource_Misc x_refsource_misc
https://github.com/lepture/mistune/releases/tag/v3.3.0
Scores
CVSS v3
7.5
EPSS
0.0041
EPSS Percentile
33.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1333
CWE-407
Status
published
Products (3)
lepture/mistune
< 3.3.0
mistune_project/mistune
< 3.3.0
pypi/mistune
0 - 3.3.0PyPI
Published
Jul 08, 2026
Tracked Since
Jul 08, 2026