{"schema_version":1,"title":"mistune (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 20 vulnerabilities in mistune (PyPI): 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-76098, was published on 24 August 2026.","url":"https://junglewise.ai/threats/technologies/mistune","json_url":"https://junglewise.ai/threats/technologies/mistune.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/mistune","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":20,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":10,"last_365_days":17},"latest":[{"cve":"CVE-2026-76098","cvss":7.5,"epss":0.0049,"slug":"cve-2026-76098-mistune-uncontrolled-recursion-in-html-rendering","title":"Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tok","severity":"high","exploited":false,"published_at":"2026-08-24T20:17:19.33+00:00","url":"https://junglewise.ai/threats/cve-2026-76098-mistune-uncontrolled-recursion-in-html-rendering"},{"cve":"CVE-2026-59930","cvss":4.3,"epss":0.0019,"slug":"cve-2026-59930-lepture-mistune-predictable-id-generation-in-toc-plugin","title":"lepture Mistune predictable ID generation in TOC plugin","severity":"medium","exploited":false,"published_at":"2026-07-08T17:17:28.867+00:00","url":"https://junglewise.ai/threats/cve-2026-59930-lepture-mistune-predictable-id-generation-in-toc-plugin"},{"cve":"CVE-2026-59929","cvss":6.1,"epss":0.0034,"slug":"cve-2026-59929-lepture-mistune-xss-via-incomplete-url-scheme-filtering-in-html","title":"lepture mistune XSS via incomplete URL scheme filtering in HTML renderer","severity":"medium","exploited":false,"published_at":"2026-07-08T17:17:28.737+00:00","url":"https://junglewise.ai/threats/cve-2026-59929-lepture-mistune-xss-via-incomplete-url-scheme-filtering-in-html"},{"cve":"CVE-2026-59928","cvss":7.5,"epss":0.0065,"slug":"cve-2026-59928-lepture-mistune-denial-of-service-in-reference-link-parsing","title":"lepture Mistune denial of service in reference-link parsing","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:28.6+00:00","url":"https://junglewise.ai/threats/cve-2026-59928-lepture-mistune-denial-of-service-in-reference-link-parsing"},{"cve":"CVE-2026-59927","cvss":5.3,"epss":0.0053,"slug":"cve-2026-59927-lepture-mistune-uncontrolled-recursion-in-include-directive","title":"lepture Mistune uncontrolled recursion in Include directive","severity":"medium","exploited":false,"published_at":"2026-07-08T17:17:28.45+00:00","url":"https://junglewise.ai/threats/cve-2026-59927-lepture-mistune-uncontrolled-recursion-in-include-directive"},{"cve":"CVE-2026-59926","cvss":4,"epss":0.0033,"slug":"cve-2026-59926-lepture-mistune-xss-in-admonition-directive","title":"lepture Mistune XSS in Admonition directive","severity":"medium","exploited":false,"published_at":"2026-07-08T17:17:28.323+00:00","url":"https://junglewise.ai/threats/cve-2026-59926-lepture-mistune-xss-in-admonition-directive"},{"cve":"CVE-2026-59925","cvss":7.5,"epss":0.0064,"slug":"cve-2026-59925-mistune-denial-of-service-via-quadratic-emphasis-parsing","title":"Mistune denial of service via quadratic emphasis parsing","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:28.183+00:00","url":"https://junglewise.ai/threats/cve-2026-59925-mistune-denial-of-service-via-quadratic-emphasis-parsing"},{"cve":"CVE-2026-59924","cvss":5.9,"epss":0.0046,"slug":"cve-2026-59924-lepture-mistune-path-traversal-in-include-directive","title":"lepture Mistune path traversal in Include directive","severity":"medium","exploited":false,"published_at":"2026-07-08T17:17:28.05+00:00","url":"https://junglewise.ai/threats/cve-2026-59924-lepture-mistune-path-traversal-in-include-directive"},{"cve":"CVE-2026-59923","cvss":6.1,"epss":0.0035,"slug":"cve-2026-59923-lepture-mistune-xss-via-percent-encoded-bypass-in-safe-url","title":"lepture Mistune XSS via percent-encoded bypass in safe_url","severity":"medium","exploited":false,"published_at":"2026-07-08T17:17:27.91+00:00","url":"https://junglewise.ai/threats/cve-2026-59923-lepture-mistune-xss-via-percent-encoded-bypass-in-safe-url"},{"cve":"CVE-2026-59922","cvss":7.5,"epss":0.0064,"slug":"cve-2026-59922-lepture-mistune-denial-of-service-in-formatting-plugins","title":"lepture Mistune denial of service in formatting plugins","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:27.77+00:00","url":"https://junglewise.ai/threats/cve-2026-59922-lepture-mistune-denial-of-service-in-formatting-plugins"},{"cve":"CVE-2026-49851","cvss":7.5,"epss":0.0063,"slug":"cve-2026-49851-lepture-mistune-cpu-exhaustion-dos-in-parse-link-text","title":"lepture Mistune CPU exhaustion DoS in parse_link_text","severity":"high","exploited":false,"published_at":"2026-06-24T18:17:18.937+00:00","url":"https://junglewise.ai/threats/cve-2026-49851-lepture-mistune-cpu-exhaustion-dos-in-parse-link-text"},{"cve":"CVE-2026-44899","cvss":4.7,"epss":0.0027,"slug":"cve-2026-44899-lepture-mistune-css-injection-in-image-directive-plugin","title":"lepture Mistune CSS injection in Image directive plugin","severity":"medium","exploited":false,"published_at":"2026-05-26T21:16:39.953+00:00","url":"https://junglewise.ai/threats/cve-2026-44899-lepture-mistune-css-injection-in-image-directive-plugin"},{"cve":"CVE-2026-44898","cvss":6.1,"epss":0.0027,"slug":"cve-2026-44898-lepture-mistune-xss-in-table-of-contents-generation","title":"lepture Mistune XSS in Table of Contents generation","severity":"medium","exploited":false,"published_at":"2026-05-26T21:16:39.81+00:00","url":"https://junglewise.ai/threats/cve-2026-44898-lepture-mistune-xss-in-table-of-contents-generation"},{"cve":"CVE-2026-44897","cvss":6.1,"epss":0.0027,"slug":"cve-2026-44897-mistune-xss-via-unsanitized-heading-id-attribute","title":"Mistune XSS via unsanitized heading ID attribute","severity":"medium","exploited":false,"published_at":"2026-05-26T21:16:39.657+00:00","url":"https://junglewise.ai/threats/cve-2026-44897-mistune-xss-via-unsanitized-heading-id-attribute"},{"cve":"CVE-2026-44896","cvss":6.1,"epss":0.0027,"slug":"cve-2026-44896-lepture-mistune-xss-in-figure-directive-image-attributes","title":"lepture Mistune XSS in Figure directive image attributes","severity":"medium","exploited":false,"published_at":"2026-05-26T21:16:39.477+00:00","url":"https://junglewise.ai/threats/cve-2026-44896-lepture-mistune-xss-in-figure-directive-image-attributes"},{"cve":"CVE-2026-44708","cvss":6.1,"epss":0.0027,"slug":"cve-2026-44708-mistune-math-plugin-xss-bypass-in-markdown-rendering","title":"Mistune math plugin XSS bypass in Markdown rendering","severity":"medium","exploited":false,"published_at":"2026-05-26T21:16:38.527+00:00","url":"https://junglewise.ai/threats/cve-2026-44708-mistune-math-plugin-xss-bypass-in-markdown-rendering"},{"cve":"CVE-2026-33079","cvss":7.5,"epss":0.007,"slug":"cve-2026-33079-mistune-redos-in-link-title-re","title":"Mistune ReDoS in LINK_TITLE_RE","severity":"high","exploited":false,"published_at":"2026-05-06T18:16:03.097+00:00","url":"https://junglewise.ai/threats/cve-2026-33079-mistune-redos-in-link-title-re"},{"cve":"CVE-2022-34749","cvss":3.1,"epss":0.0153,"slug":"cve-2022-34749-mistune-vulnerable-to-catastrophic-backtracking","title":"PYSEC-2022-237 - In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtrackin","severity":"low","exploited":false,"published_at":"2022-07-25T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-34749-mistune-vulnerable-to-catastrophic-backtracking"},{"cve":"CVE-2017-16876","cvss":3.1,"epss":0.0224,"slug":"cve-2017-16876-mistune-cross-site-scripting-xss-vulnerability","title":"PYSEC-2017-18 - Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arb","severity":"low","exploited":false,"published_at":"2017-12-29T15:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-16876-mistune-cross-site-scripting-xss-vulnerability"},{"cve":"CVE-2017-15612","cvss":3,"epss":0.0092,"slug":"cve-2017-15612-cross-site-scripting-in-mistune","title":"PYSEC-2017-80 - mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\\nscript:) or a crafted email address, related to the escap","severity":"low","exploited":false,"published_at":"2017-10-19T08:29:00+00:00","url":"https://junglewise.ai/threats/cve-2017-15612-cross-site-scripting-in-mistune"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"mistune (PyPI)","slug":"mistune","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/mistune/","repo_url":"https://github.com/lepture/mistune","description":"A fast Markdown parser for Python with support for renderers and extensions.","url":"https://junglewise.ai/threats/technologies/mistune"},"most_severe":[{"cve":"CVE-2026-33079","cvss":7.5,"epss":0.007,"slug":"cve-2026-33079-mistune-redos-in-link-title-re","title":"Mistune ReDoS in LINK_TITLE_RE","severity":"high","exploited":false,"published_at":"2026-05-06T18:16:03.097+00:00","url":"https://junglewise.ai/threats/cve-2026-33079-mistune-redos-in-link-title-re"},{"cve":"CVE-2026-59928","cvss":7.5,"epss":0.0065,"slug":"cve-2026-59928-lepture-mistune-denial-of-service-in-reference-link-parsing","title":"lepture Mistune denial of service in reference-link parsing","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:28.6+00:00","url":"https://junglewise.ai/threats/cve-2026-59928-lepture-mistune-denial-of-service-in-reference-link-parsing"},{"cve":"CVE-2026-59925","cvss":7.5,"epss":0.0064,"slug":"cve-2026-59925-mistune-denial-of-service-via-quadratic-emphasis-parsing","title":"Mistune denial of service via quadratic emphasis parsing","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:28.183+00:00","url":"https://junglewise.ai/threats/cve-2026-59925-mistune-denial-of-service-via-quadratic-emphasis-parsing"},{"cve":"CVE-2026-59922","cvss":7.5,"epss":0.0064,"slug":"cve-2026-59922-lepture-mistune-denial-of-service-in-formatting-plugins","title":"lepture Mistune denial of service in formatting plugins","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:27.77+00:00","url":"https://junglewise.ai/threats/cve-2026-59922-lepture-mistune-denial-of-service-in-formatting-plugins"},{"cve":"CVE-2026-49851","cvss":7.5,"epss":0.0063,"slug":"cve-2026-49851-lepture-mistune-cpu-exhaustion-dos-in-parse-link-text","title":"lepture Mistune CPU exhaustion DoS in parse_link_text","severity":"high","exploited":false,"published_at":"2026-06-24T18:17:18.937+00:00","url":"https://junglewise.ai/threats/cve-2026-49851-lepture-mistune-cpu-exhaustion-dos-in-parse-link-text"},{"cve":"CVE-2026-76098","cvss":7.5,"epss":0.0049,"slug":"cve-2026-76098-mistune-uncontrolled-recursion-in-html-rendering","title":"Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tok","severity":"high","exploited":false,"published_at":"2026-08-24T20:17:19.33+00:00","url":"https://junglewise.ai/threats/cve-2026-76098-mistune-uncontrolled-recursion-in-html-rendering"},{"cve":"CVE-2026-59923","cvss":6.1,"epss":0.0035,"slug":"cve-2026-59923-lepture-mistune-xss-via-percent-encoded-bypass-in-safe-url","title":"lepture Mistune XSS via percent-encoded bypass in safe_url","severity":"medium","exploited":false,"published_at":"2026-07-08T17:17:27.91+00:00","url":"https://junglewise.ai/threats/cve-2026-59923-lepture-mistune-xss-via-percent-encoded-bypass-in-safe-url"},{"cve":"CVE-2026-59929","cvss":6.1,"epss":0.0034,"slug":"cve-2026-59929-lepture-mistune-xss-via-incomplete-url-scheme-filtering-in-html","title":"lepture mistune XSS via incomplete URL scheme filtering in HTML renderer","severity":"medium","exploited":false,"published_at":"2026-07-08T17:17:28.737+00:00","url":"https://junglewise.ai/threats/cve-2026-59929-lepture-mistune-xss-via-incomplete-url-scheme-filtering-in-html"},{"cve":"CVE-2026-44898","cvss":6.1,"epss":0.0027,"slug":"cve-2026-44898-lepture-mistune-xss-in-table-of-contents-generation","title":"lepture Mistune XSS in Table of Contents generation","severity":"medium","exploited":false,"published_at":"2026-05-26T21:16:39.81+00:00","url":"https://junglewise.ai/threats/cve-2026-44898-lepture-mistune-xss-in-table-of-contents-generation"},{"cve":"CVE-2026-44897","cvss":6.1,"epss":0.0027,"slug":"cve-2026-44897-mistune-xss-via-unsanitized-heading-id-attribute","title":"Mistune XSS via unsanitized heading ID attribute","severity":"medium","exploited":false,"published_at":"2026-05-26T21:16:39.657+00:00","url":"https://junglewise.ai/threats/cve-2026-44897-mistune-xss-via-unsanitized-heading-id-attribute"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}