CVE-2022-34749
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
02 / AFFECTED SOFTWARE
Affected packages
29 explicit affected versions
10 explicit affected versions
10 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
In Mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/34xxx/CVE-2022-34749.json
- https://github.com/lepture/mistune/commit/a6d43215132fe4f3d93f8d7e90ba83b16a0838b2
- https://github.com/lepture/mistune/releases
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQHXITQ2DSBYOILKHXBSBB7PFBPZHF63/
- https://nvd.nist.gov/vuln/detail/CVE-2022-34749
- https://github.com/lepture/mistune
- https://github.com/lepture/mistune/commit/ca1e7b506850f4e488823fc7338b49a8f9852718
- https://github.com/lepture/mistune/issues/314#issuecomment-1223972386
- https://github.com/pypa/advisory-database/tree/main/vulns/mistune/PYSEC-2022-237.yaml
- https://lists.fedoraproject.org/archives/list/[email protected]/message/TQHXITQ2DSBYOILKHXBSBB7PFBPZHF63
- https://github.com/advisories/GHSA-fw3v-x4f2-v673