THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-33079 (HIGH 7.5) — In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular expression used for parsing link titles conta

[NVD] CVE-2026-33079 (HIGH 7.5) — In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular expression used for parsing link titles conta

lownvdPublished 2026-05-06

CVE-2026-33079 CVSS: 7.5 HIGH Published: 2026-05-06T18:16:03.097

In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular expression used for parsing link titles contains overlapping alternatives that can trigger catastro

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-33079