Mistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
Summary
| CVE | CVE-2026-33079 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-06 18:16:03 UTC |
| Updated | 2026-08-28 16:17:28 UTC |
| Description | In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular expression used for parsing link titles contains overlapping alternatives that can trigger catastrophic backtracking. In both the double-quoted and single-quoted branches, a backslash followed by punctuation can be matched either as an escaped punctuation sequence or as two ordinary characters, creating an ambiguous pattern inside a repeated group. If an attacker supplies Markdown containing repeated ! sequences with no closing quote, the regex engine explores an exponential number of backtracking paths. This is reachable through normal Markdown parsing of inline links and block link reference definitions. A small crafted input can therefore cause significant CPU consumption and make applications using Mistune unresponsive. |
Risk And Classification
Primary CVSS: v4.0 8.7 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.005280000 probability, percentile 0.426060000 (date 2026-08-30)
Problem Types: CWE-1333 | CWE-1333 CWE-1333: Inefficient Regular Expression Complexity | CWE-1333 Inefficient Regular Expression Complexity
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| 3.1 | ADP | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Lepture | Mistune | affected >=3.0.0a1, <= 3.2.0 | Not specified |
| ADP | Red Hat | Red Hat Migration Toolkit For Applications 8.2 | unaffected 1784109883 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073866 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073936 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073873 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073459 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073611 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073451 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073451 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787076778 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787077779 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787076481 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787074331 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073913 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787074078 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073929 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073605 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073546 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073717 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073713 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073593 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat Satellite 6 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2026:43038 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| github.com/lepture/mistune/security/advisories/GHSA-8mp2-v27r-99xp | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | github.com | |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| github.com/lepture/mistune/blob/df23edd60b43b639d2e6760ef9dd3d618aa11c21... | [email protected] | github.com | |
| access.redhat.com/security/cve/CVE-2026-33079 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33079.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60520 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-05-06T18:01:13.818Z | Reported to Red Hat. |
| ADP | 2026-05-06T17:25:09.026Z | Made public. |
Solutions
ADP: RHSA-2026:43038: Red Hat Migration Toolkit for Applications 8.2
ADP: RHSA-2026:60520: Red Hat OpenShift AI 3.4
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.