CVE-2026-49851: Lepture Mistune
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. When parsing Markdown containing many consecutive [ characters, parse_link_text repeatedly scans the input using a regex search inside a loop. Each iteration re-scans a large portion of the remaining string, resulting in quadratic-time behavior. An attacker-controlled Markdown input can therefore trigger excessive CPU usage with a very small payload. This vulnerability is fixed in 3.3.0.
Affected products
- Lepture Mistune: before 3.3.0 (fixed in 3.3.0)
- Red Hat Migration Toolkit For Applications 8
- Red Hat Red Hat Openshift Ai 3.4: before 1787073866 (fixed in 1787073866); before 1787073936 (fixed in 1787073936); before 1787073873 (fixed in 1787073873); before 1787073459 (fixed in 1787073459); before 1787073611 (fixed in 1787073611); before 1787073451 (fixed in 1787073451); …
- Red Hat Red Hat Openshift Ai Rhoai
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Satellite 6
Published 2026-06-24. Last modified 2026-08-28.