CVE-2026-59925
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
7.5
HIGH
CVSS 3.1
EPSS 0.36%
Description
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from every potential opening run, allowing denial of service in default Mistune parsing. This issue is fixed in version 3.3.0.
How to fix CVE-2026-59925
To remediate CVE-2026-59925, upgrade the affected package to a fixed version below.
- —upgrade to 3.3.0 or later
Is CVE-2026-59925 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.3.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |