Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92220.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92220
Upstream
Published
2026-07-08T17:17:27Z
Modified
2026-09-09T06:55:05Z
Summary
CVE-2026-59922 affecting package python-mistune for versions less than 3.3.0-1
Details

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each possible start position, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.

References

Affected packages

Azure Linux:3 / python-mistune

Package

Name
python-mistune
Purl
pkg:rpm/azure-linux/python-mistune

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.3.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92220.json"