Mistune Project maintains a focused markdown-parsing library whose simplicity belies its broad integration across documentation systems, static site generators, and web applications that process user-supplied markdown. The vendor's vulnerability profile centers on the library's text-processing role, with durable signals in cross-site scripting defects during HTML generation and regular-expression complexity issues that can degrade performance under crafted input. Defenders should track this library's updates when it is embedded in internet-facing systems that accept user markdown; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mistune Project over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59928HIGH Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-59925HIGH Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character c | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-59922HIGH Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work i | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-59924MEDIUM Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result r | Jul 8, 2026 | 5.9 | 30 | NO | NO |
CVE-2026-59929MEDIUM Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:, vbscript:, file:, and | Jul 8, 2026 | 6.1 | 30 | NO | NO |
CVE-2026-59926MEDIUM Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :c | Jul 8, 2026 | 6.1 | 30 | NO | NO |
CVE-2026-59923MEDIUM Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied M | Jul 8, 2026 | 6.1 | 29 | NO | NO |
CVE-2026-59927MEDIUM Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not | Jul 8, 2026 | 5.3 | 28 | NO | NO |
CVE-2026-44896MEDIUM Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and fig | May 26, 2026 | 6.1 | 27 | NO | NO |
CVE-2026-44897MEDIUM Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value di | May 26, 2026 | 6.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mistune Project.
Media articles that mention a CVE ID that affects a product developed by Mistune Project — matched by CVE ID, not by vendor name.