CVE-2026-59925
lepture mistune
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from every potential opening run, allowing denial of service in default Mistune parsing. This issue is fixed in version 3.3.0.
- CVSS
- 7.5
- EPSS
- 0.36% 28.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.09