Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3863
  • PyPI/mistune
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown 10 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-6m44-fpc8-c3rq
  • PyPI/mistune
Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown 02 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-qfrw-5rxm-mhh2
  • PyPI/mistune
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution 20 Jul
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-2hm2-hc3v-44h9
  • PyPI/mistune
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content 20 Jul
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-r4rv-85jg-w4mf
  • PyPI/mistune
Mistune: Arbitrary File Read via Include directive path traversal 20 Jul
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-c8j7-8cv4-2xmq
  • PyPI/mistune
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert) 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-g97x-gvcm-x72h
  • PyPI/mistune
Mistune: XSS via unescaped class option in Admonition directive 20 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-8c25-4j27-2rv3
  • PyPI/mistune
Mistune: XSS via percent-encoded javascript URI bypass in safe_url() 20 Jul
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-4j32-57v6-6g45
  • PyPI/mistune
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-8mpj-m6qm-5qr8
  • PyPI/mistune
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files 20 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-ffq3-xpv3-j92q
  • PyPI/mistune
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions 20 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2652
  • PyPI/mistune
Mistune: Potential DoS via quadratic-time parsing in parse_link_text 13 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2651
  • PyPI/mistune
Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input 13 Jul
  • Fix available
  • Severity - 8.7 (High)
GHSA-qcq2-496w-v96p
  • PyPI/mistune
Mistune: Potential DoS via quadratic-time parsing in parse_link_text 09 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2218
  • PyPI/mistune
See record for full details 08 Jul
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-2217
  • PyPI/mistune
See record for full details 08 Jul
  • Fix available
  • Severity - 6.1 (Medium)