DEBIAN-CVE-2026-59927

Source
https://security-tracker.debian.org/tracker/CVE-2026-59927
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59927.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-59927
Upstream
Published
2026-07-08T17:17:28.450Z
Modified
2026-07-09T09:00:27.669367217Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionError, and crash the rendering request. This issue is fixed in version 3.3.0.

References

Affected packages

Debian:11 / mistune

Package

Name
mistune
Purl
pkg:deb/debian/mistune?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.8.4-4
0.8.4-5
2.*
2.0.0~rc1-1~exp1
2.0.0-1
2.0.0-1+really0.8.4-1
2.0.0.0+really2.0.0-1~exp1
2.0.0.0+really2.0.0-1
2.0.2-1
2.0.3-1
2.0.4-1
2.0.4-2
3.*
3.0.2-1
3.0.2-2
3.1.3-1
3.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59927.json"

Debian:12 / mistune

Package

Name
mistune
Purl
pkg:deb/debian/mistune?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.4-1
2.0.4-2
3.*
3.0.2-1
3.0.2-2
3.1.3-1
3.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59927.json"

Debian:13 / mistune

Package

Name
mistune
Purl
pkg:deb/debian/mistune?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.3-1
3.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59927.json"

Debian:14 / mistune

Package

Name
mistune
Purl
pkg:deb/debian/mistune?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.3-1
3.1.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-59927.json"