VendorsMistune Projectmistuneany version
Vulnerabilities

Mistune Project Mistune any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2022-34749
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
Published 2022-07-25 · Modified
7.5EPSS 0.015
CVE-2026-59928
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
Published 2026-07-08 · Analyzed
7.5EPSS 0.007
CVE-2026-59922
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
Published 2026-07-08 · Analyzed
7.5EPSS 0.006
CVE-2026-59925
inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
Published 2026-07-08 · Analyzed
7.5EPSS 0.006
CVE-2017-16876
Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.
Published 2017-12-29 · Modified
6.1EPSS 0.022
CVE-2026-59923
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
Published 2026-07-08 · Analyzed
6.1EPSS 0.003
CVE-2026-59929
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Published 2026-07-08 · Analyzed
6.1EPSS 0.003
CVE-2026-59926
Mistune: XSS via unescaped class option in Admonition directive
Published 2026-07-08 · Analyzed
6.1EPSS 0.003
CVE-2026-44708
Mistune Math Plugin XSS Escape Bypass
Published 2026-05-26 · Analyzed
6.1EPSS 0.003
CVE-2026-44896
Mistune: XSS via unescaped figclass/figwidth in Figure directive
Published 2026-05-26 · Modified
6.1EPSS 0.003
CVE-2026-44897
Mistune Heading ID Attribute Injection XSS
Published 2026-05-26 · Analyzed
6.1EPSS 0.003
CVE-2026-44898
Mistune TOC Anchor Injection XSS
Published 2026-05-26 · Analyzed
6.1EPSS 0.003
CVE-2026-44899
Mistune Image Directive CSS Injection Vulnerability
Published 2026-05-26 · Analyzed
6.1EPSS 0.003
CVE-2026-59924
Mistune: Arbitrary File Read via Include directive path traversal
Published 2026-07-08 · Analyzed
5.9EPSS 0.005
CVE-2026-59927
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
Published 2026-07-08 · Analyzed
5.3EPSS 0.005
CVE-2026-59930
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
Published 2026-07-08 · Analyzed
4.3EPSS 0.002