CVE-2026-49851: Mistune: Potential DoS via quadratic-time parsing in parse_link_text
Summary Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parselinktext. A relatively small input consisting of repeated [ characters causes significant parsing slowdown.
Affected component mistune/inlineparser.py → parselinktext
Description When parsing Markdown containing many consecutive [ characters, parselinktext repeatedly scans the input using a regex search inside a loop. Each iteration re-scans a large portion of the remaining string, resulting in quadratic-time behavior. An attacker-controlled Markdown input can therefore trigger excessive CPU usage with a very small payload.
Root cause The vulnerability stems from a two-loop interaction: - The outer loop in InlineParser.parse() (inlineparser.py) advances only 1 character at a time when parselink() returns None - Each failed attempt calls parselinktext() which performs an O(n) scan to the end of the string looking for a closing ] - With n consecutive [ characters, this results in O(n) × O(n) = O(n²) total work
PoC Run below python script import mistune import time
md = mistune.createmarkdown()
s = "[" 6400
t = time.perfcounter() md(s) print(time.perfcounter() - t) <img width="2028" height="1277" alt="image" src="https://github.com/user-attachments/assets/15d5bc0b-35f8-4a15-85e0-cbc314a45b06" />
Benmark poc Run below code for benchmark import mistune import time
md = mistune.createmarkdown()
sizes = [100,200,400,800,1600,3200,6400]
for n in sizes: s = "[" n
t0 = time.perfcounter() md(s) dt = time.perfcounter() - t0
print(f"{n:6d} {dt:.6f}") <img width="2503" height="1341" alt="image" src="https://github.com/user-attachments/assets/f09a7bbb-6927-4ba2-afb1-444dd913b84e" />
Observed behaviour python3 benchmark.py 100 0.001609 200 0.003207 400 0.012906 800 0.050220 1600 0.197307 3200 0.801172 6400 3.190393 Execution time grows superlinearly, consistent with O(n²) complex
Impact This can be used as a denial-of-service attack in any application that parses user-supplied Markdown using Mistune, including:
- Web applications (comments, posts, content rendering) - API services processing Markdown - Documentation rendering systems - A small (~6 KB) payload can block CPU for multiple seconds.
Suggested fix Return the furthest scanned position from parselinktext even on failure, so the outer loop can skip ahead instead of advancing 1 character at a time
Security Classification CWE-400: Uncontrolled Resource Consumption Denial of Service (CPU exhaustion)
Other sources
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parselinktext. When parsing Markdown containing many consecutive [ characters, parselinktext repeatedly scans the input using a regex search inside a loop. Each iteration re-scans a large portion of the remaining string, resulting in quadratic-time behavior. An attacker-controlled Markdown input can therefore trigger excessive CPU usage with a very small payload. This vulnerability is fixed in 3.3.0.
— NVD
Mistune: Potential DoS via quadratic-time parsing in parselinktext
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.3.0-1 - Upgrade
Upgrade
pip/mistuneto a version that resolves this vulnerability.Fixed in 3.3.0 - Upgrade
Upgrade
mistuneto a version that resolves this vulnerability.Fixed in 3.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49851?
CVE-2026-49851 has a high severity rating of 8.7.
How do I fix CVE-2026-49851?
To address CVE-2026-49851, upgrade Mistune to version 3.3.0 or later.
What type of attack does CVE-2026-49851 enable?
CVE-2026-49851 enables a denial-of-service (DoS) attack due to CPU exhaustion.
What versions of Mistune are affected by CVE-2026-49851?
CVE-2026-49851 affects all versions of Mistune prior to 3.3.0.
What is the cause of the vulnerability in CVE-2026-49851?
The vulnerability is caused by superlinear parsing behavior in the parse_link_text function when handling many consecutive '[' characters.