Executive brief
Mistune, a popular Python library for converting Markdown text to HTML, is vulnerable to a denial-of-service attack. By providing a specially crafted, very small Markdown snippet, an attacker can cause the application to consume excessive CPU resources, effectively freezing the service. This can lead to application unresponsiveness for any platform that allows users to submit Markdown content, such as comment sections, documentation portals, or CMS platforms.
Technical details
A Regular Expression Denial of Service (ReDoS) exists in Mistune's `LINK_TITLE_RE` component due to overlapping alternatives in the regex pattern used for parsing link titles. Specifically, the regex allows a backslash followed by punctuation to be matched in two different ways (as an escaped sequence or as two individual characters), creating ambiguity within a repeated group. When an attacker provides a Markdown string with repeated backslash-punctuation pairs (e.g., `\!`) without a closing quote, the regex engine performs exponential backtracking (O(2^N)). This is reachable via both inline links and block link reference definitions. A payload as small as 58 bytes can block the parser for several seconds. No patch was officially listed as released in the advisory, though a fix involving excluding the backslash from the catch-all character class was suggested.
Affected products
- lepture mistune >=3.0.0a1, <= 3.2.0
- Red Hat Migration Toolkit for Applications 8
- Red Hat Red Hat OpenShift AI (RHOAI)
- Red Hat Red Hat Satellite 6
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
References
- https://github.com/lepture/mistune/blob/df23edd60b43b639d2e6760ef9dd3d618aa11c21/src/mistune/helpers.py
- https://github.com/lepture/mistune/security/advisories/GHSA-8mp2-v27r-99xp
- https://access.redhat.com/security/cve/CVE-2026-33079
- https://bugzilla.redhat.com/show_bug.cgi?id=2467298
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33079.json