THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6m44-fpc8-c3rq (high) — Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

[GHSA] GHSA-6m44-fpc8-c3rq (high) — Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

medgithub_advisoriesPublished 2026-09-02

GHSA-6m44-fpc8-c3rq Severity: high CVE: CVE-2026-76098

Mistune: Denial of Service — RecursionError via Excessive Emphasis Markers in Markdown

## Summary Mistune v3.3.2 is vulnerable to a Denial of Service (DoS) attack via uncontrolled recursion in the HTML rendering of deeply-nested emphasis tokens. By submitting Markdown containing approximately 1,000 consecutive asterisk characters, an attacke

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6m44-fpc8-c3rq