VDB

PYSEC-2022-237

PYSEC-2022-237 PUBLISHED

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

Affected Products

VendorProductVersions
PyPImistune0, 2.0.0a1, 2.0.0

Timeline

  • Jul 25, 2022 CVE Published
  • Nov 8, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›