CVE-2022-34749
published 2022-07-25CVE-2022-34749: In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.21%
64.8th percentile
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mistune | < mistune 2.0.3-1 (bookworm) | mistune 2.0.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| mistune_project | mistune | <= 2.0.2 | — |
| mistune_project | mistune | >= 0 < 2.0.3-1 | 2.0.3-1 |
| mistune_project | mistune | >= 0 < 2.0.3-1 | 2.0.3-1 |
| mistune_project | mistune | >= 0 < 2.0.3-1 | 2.0.3-1 |
| mistune_project | mistune | >= 2.0.0a1 < 2.0.3 | 2.0.3 |
| msrc | cbl2_python-mistune_0.8.3-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_python-mistune_0.8.3-3_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mistune vulnerable to catastrophic backtracking
ghsa·2022-07-26
CVE-2022-34749 [HIGH] CWE-1333 Mistune vulnerable to catastrophic backtracking
Mistune vulnerable to catastrophic backtracking
In Mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
OSV
Mistune vulnerable to catastrophic backtracking
osv·2022-07-26
CVE-2022-34749 [HIGH] Mistune vulnerable to catastrophic backtracking
Mistune vulnerable to catastrophic backtracking
In Mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
OSV
CVE-2022-34749: In mistune through 2
osv·2022-07-25·CVSS 7.5
CVE-2022-34749 [HIGH] CVE-2022-34749: In mistune through 2
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
Red Hat
mistune: catastrophic backtracking
vendor_redhat·2022-07-26·CVSS 7.5
CVE-2022-34749 [HIGH] CWE-1333 mistune: catastrophic backtracking
mistune: catastrophic backtracking
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
A regular expression denial of service (ReDoS) flaw was found in the asteris emphasis regular expression implementation in Mistune. By sending specially-crafted regex input, a remote attacker could invoke a catastrophic backtrack, resulting in a denial of service.
Package: python-mistune (Red Hat Ceph Storage 6) - Will not fix
Package: python-mistune (Red Hat OpenShift Container Platform 4) - Affected
Microsoft
In mistune through 2.0.2 support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named cata
vendor_msrc·2022-07-12·CVSS 7.5
CVE-2022-34749 [HIGH] CWE-1333 In mistune through 2.0.2 support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named cata
In mistune through 2.0.2 support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identifi
Debian
CVE-2022-34749: mistune - In mistune through 2.0.2, support of inline markup is implemented by using regul...
vendor_debian·2022·CVSS 7.5
CVE-2022-34749 [HIGH] CVE-2022-34749: mistune - In mistune through 2.0.2, support of inline markup is implemented by using regul...
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
Scope: local
bookworm: resolved (fixed in 2.0.3-1)
bullseye: open
forky: resolved (fixed in 2.0.3-1)
sid: resolved (fixed in 2.0.3-1)
trixie: resolved (fixed in 2.0.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/lepture/mistune/commit/a6d43215132fe4f3d93f8d7e90ba83b16a0838b2https://github.com/lepture/mistune/releaseshttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQHXITQ2DSBYOILKHXBSBB7PFBPZHF63/https://github.com/lepture/mistune/commit/a6d43215132fe4f3d93f8d7e90ba83b16a0838b2https://github.com/lepture/mistune/releaseshttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQHXITQ2DSBYOILKHXBSBB7PFBPZHF63/
2022-07-25
Published