Junglewise Threat Intelligence

CVE-2026-49851: lepture Mistune CPU exhaustion DoS in parse_link_text

CVE-2026-49851 · Severity: high · CVSS 7.5 · Published 2026-06-24

Technologies: Lepture Mistune. Vendors: PyPI.

Executive brief

Mistune, a popular Python library for parsing Markdown text, is vulnerable to a denial-of-service (DoS) flaw. An attacker can provide a specially crafted Markdown snippet—such as a long string of opening brackets—that causes the library to consume excessive CPU resources. This can lead to application slowdowns or complete service outages for web platforms that process user-generated content like comments or documentation.

Technical details

A denial-of-service vulnerability exists in Mistune's inline parser due to inefficient handling of link text. The root cause is a nested loop interaction between `InlineParser.parse()` and `parse_link_text()`: the outer loop advances only one character at a time when a link match fails, while the inner loop performs a full linear scan for a closing bracket. When processing a string with many consecutive '[' characters, this results in O(n²) quadratic-time complexity. An unauthenticated remote attacker can exploit this by submitting a small (~6 KB) Markdown payload to trigger high CPU utilization. The issue is fixed in version 3.3.0 by ensuring the parser skips ahead to the furthest scanned position after a failed match.

Affected products

  • lepture mistune < 3.3.0

Timeline

  • 2026-06-21: disclosed
  • 2026-06-24: advisory: NVD publication
  • 2026-07-09: patched: GitHub Advisory reviewed and updated with patch version 3.3.0

References

Related threats