Executive brief
Mistune, a popular Python library for parsing Markdown text, is vulnerable to a denial-of-service (DoS) flaw. An attacker can provide a specially crafted Markdown snippet—such as a long string of opening brackets—that causes the library to consume excessive CPU resources. This can lead to application slowdowns or complete service outages for web platforms that process user-generated content like comments or documentation.
Technical details
A denial-of-service vulnerability exists in Mistune's inline parser due to inefficient handling of link text. The root cause is a nested loop interaction between `InlineParser.parse()` and `parse_link_text()`: the outer loop advances only one character at a time when a link match fails, while the inner loop performs a full linear scan for a closing bracket. When processing a string with many consecutive '[' characters, this results in O(n²) quadratic-time complexity. An unauthenticated remote attacker can exploit this by submitting a small (~6 KB) Markdown payload to trigger high CPU utilization. The issue is fixed in version 3.3.0 by ensuring the parser skips ahead to the furthest scanned position after a failed match.
Affected products
- lepture mistune < 3.3.0
Timeline
- 2026-06-21: disclosed
- 2026-06-24: advisory: NVD publication
- 2026-07-09: patched: GitHub Advisory reviewed and updated with patch version 3.3.0