>= 2.0.0a1, < 2.0.3
from 0, < a6d43215132fe4f3d93f8d7e90ba83b16a0838b2 | >= 2.0.0a1, < 2.0.3
HIGH7.5CVE-2026-59928Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions from 0, < 3.3.0
HIGH7.5Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
from 0, < 3.3.0
HIGH7.5Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
from 0, < 3.3.0
HIGH7.5Mistune: Potential DoS via quadratic-time parsing in parse_link_text
from 0, < 3.3.0
HIGH7.5Mistune: Potential DoS via quadratic-time parsing in parse_link_text
from 0, < 3.3.0
MEDIUM6.1Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
from 0, < 3.3.0
MEDIUM6.1Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
from 0, < 3.3.0
MEDIUM6.1Mistune TOC Anchor Injection XSS
>= 3.2.0, < 3.2.1
MEDIUM6.1Mistune TOC Anchor Injection XSS
from 0, < 3.2.1
MEDIUM6.1Mistune Heading ID Attribute has Injection XSS
from 0, < 3.2.1
MEDIUM6.1Mistune Heading ID Attribute has Injection XSS
from 0, < 3.2.1
MEDIUM6.1Mistune has XSS via unescaped figclass/figwidth in Figure directive
from 0, < 3.2.1
MEDIUM6.1Mistune has XSS via unescaped figclass/figwidth in Figure directive
from 0, < 3.2.1
MEDIUM6.1Mistune Math Plugin has an XSS Escape Bypass
from 0, <= 3.2.0
MEDIUM6.1Mistune Math Plugin has an XSS Escape Bypass
from 0, < 3.2.1
MEDIUM6.1Cross-site Scripting in Mistune
from 0, < 0.8
MEDIUM6.1Cross-site Scripting in Mistune
from 0, < 0.8
MEDIUM6.1mistune Cross-site scripting (XSS) vulnerability
from 0, < 0.8.1
MEDIUM6.1mistune Cross-site scripting (XSS) vulnerability
from 0, < 5f06d724bc05580e7f203db2d4a4905fc1127f98 | from 0, < 0.8.1
MEDIUM5.9Mistune: Arbitrary File Read via Include directive path traversal
from 0, < 3.3.0
MEDIUM5.3Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
from 0, < 3.3.0
MEDIUM4.7Mistune Image Directive CSS Injection Vulnerability
>= 3.2.0, < 3.2.1
MEDIUM4.7Mistune Image Directive CSS Injection Vulnerability
from 0, < 3.2.1
MEDIUM4.3Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
from 0, < 3.3.0
—Mistune: XSS via unescaped class option in Admonition directive
from 0, < 3.3.0
—Duplicate Advisory: Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input
>= 3.0.0a1, < 3.2.1
—Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input
>= 3.0.0a1, < 3.2.1
—Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input
>= 3.0.0a1, < 3.2.1