Mistune: Potential DoS via quadratic-time parsing in parse_link_text
Summary
| CVE | CVE-2026-49851 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-24 18:17:18 UTC |
| Updated | 2026-08-28 16:18:13 UTC |
| Description | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repeatedly scans the input using a regex search inside a loop. Each iteration re-scans a large portion of the remaining string, resulting in quadratic-time behavior. An attacker-controlled Markdown input can therefore trigger excessive CPU usage with a very small payload. This vulnerability is fixed in 3.3.0. |
Risk And Classification
Primary CVSS: v4.0 8.7 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.006300000 probability, percentile 0.477160000 (date 2026-08-30)
Problem Types: CWE-400 | CWE-407 | CWE-770 | CWE-1333 | CWE-400 CWE-400: Uncontrolled Resource Consumption | CWE-770 CWE-770: Allocation of Resources Without Limits or Throttling | CWE-407 CWE-407: Inefficient Algorithmic Complexity | CWE-1333 Inefficient Regular Expression Complexity
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| 3.1 | ADP | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Lepture | Mistune | affected < 3.3.0 | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073866 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073936 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073873 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073459 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073611 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073451 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073451 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787076778 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787077779 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787076481 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787074331 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073913 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787074078 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073929 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073605 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073546 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073717 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073713 * rpm | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI 3.4 | unaffected 1787073593 * rpm | Not specified |
| ADP | Red Hat | Migration Toolkit For Applications 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Satellite 6 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| github.com/lepture/mistune/security/advisories/GHSA-qcq2-496w-v96p | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | github.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49851.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:60520 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-49851 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-06-24T18:04:13.571Z | Reported to Red Hat. |
| ADP | 2026-06-24T17:05:33.602Z | Made public. |
Solutions
ADP: RHSA-2026:60520: Red Hat OpenShift AI 3.4
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.