REDHAT-BUG-2467298: High severity Mistune Mistune vulnerability

Published May 6, 2026
·
Updated

In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in LINKTITLERE that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular expression used for parsing link titles contains overlapping alternatives that can trigger catastrophic backtracking. In both the double-quoted and single-quoted branches, a backslash followed by punctuation can be matched either as an escaped punctuation sequence or as two ordinary characters, creating an ambiguous pattern inside a repeated group. If an attacker supplies Markdown containing repeated ! sequences with no closing quote, the regex engine explores an exponential number of backtracking paths. This is reachable through normal Markdown parsing of inline links and block link reference definitions. A small crafted input can therefore cause significant CPU consumption and make applications using Mistune unresponsive.

Affected Software

1 affected component
Mistune Mistune>=3.0.0a1<=3.2.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Mistune to a version that resolves this vulnerability.

    Fixed in 3.0.0a1 through 3.2.0
  2. Compensating control

    Mitigate by preventing untrusted users from supplying Markdown input for Mistune parsing (or strictly isolate/limit where Markdown is processed) to avoid triggering the LINK_TITLE_RE ReDoS via normal inline link and block link reference parsing.

Event History

May 6, 2026
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2467298?

The severity of REDHAT-BUG-2467298 is classified as high, with a severity score of 7.

2

How do I fix REDHAT-BUG-2467298?

To fix REDHAT-BUG-2467298, you should update Mistune to a version later than 3.2.0.

3

What kind of vulnerability is REDHAT-BUG-2467298?

REDHAT-BUG-2467298 is a Regular Expression Denial of Service (ReDoS) vulnerability.

4

What components are affected by REDHAT-BUG-2467298?

The vulnerability affects versions 3.0.0a1 through 3.2.0 of the Mistune software.

5

What impact does REDHAT-BUG-2467298 have on systems?

REDHAT-BUG-2467298 can lead to denial of service for systems that use Mistune to parse Markdown content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203