CVE-2026-59928
Description
A flaw was found in Mistune, a Python Markdown parser. A remote attacker could exploit this vulnerability by providing a specially crafted Markdown document containing numerous repeated or distinct reference-link definitions. This can lead to excessive processing, causing CPU exhaustion and a denial of service (DoS) for the affected system.
Statement
A flaw was found in Mistune, a Python Markdown parser. An attacker who can supply Markdown for parsing could exploit this vulnerability by providing a specially crafted document containing numerous repeated or distinct reference-link definitions. This triggers excessive CPU consumption during parsing, which may render affected applications unresponsive and result in a denial of service. Red Hat uses PR:L because delivering the crafted Markdown document document to Mistune will require authenticated access in affected products, platform login/RBAC prevents unauthenticated remote submission in default deployments. The upstream PR:N score assumes any Internet-facing app parsing untrusted Markdown without authentication.
Mitigation
To mitigate this issue, avoid processing untrusted Markdown documents with affected Red Hat products. Restricting the input sources to trusted content can reduce the risk of a denial of service attack.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 6.5 | N/A | 7.5 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | Low | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU)
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.