Bug 2112230 (CVE-2022-34749) - CVE-2022-34749 mistune: catastrophic backtracking
Summary: CVE-2022-34749 mistune: catastrophic backtracking
Keywords:
Status: NEW
Alias: CVE-2022-34749
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2112231 2112232 2255447 2255448 2422953
Blocks: 2111156
TreeView+ depends on / blocked
 
Reported: 2022-07-29 06:35 UTC by TEJ RATHI
Modified: 2026-02-17 00:50 UTC (History)
17 users (show)

Fixed In Version: mistune 2.0.3
Clone Of:
Environment:
Last Closed: 2022-08-30 19:33:00 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:2711 0 None None None 2026-02-16 10:42:27 UTC
Red Hat Product Errata RHSA-2026:2769 0 None None None 2026-02-17 00:50:35 UTC

Description TEJ RATHI 2022-07-29 06:35:00 UTC
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

https://github.com/lepture/mistune/commit/a6d43215132fe4f3d93f8d7e90ba83b16a0838b2
https://github.com/lepture/mistune/releases

Comment 1 TEJ RATHI 2022-07-29 06:36:21 UTC
Created python-mistune tracking bugs for this issue:

Affects: epel-all [bug 2112231]
Affects: fedora-all [bug 2112232]

Comment 2 Product Security DevOps Team 2022-08-30 19:32:59 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.

Comment 11 errata-xmlrpc 2026-02-16 10:42:25 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 8.1

Via RHSA-2026:2711 https://access.redhat.com/errata/RHSA-2026:2711

Comment 12 errata-xmlrpc 2026-02-17 00:50:32 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 7.1

Via RHSA-2026:2769 https://access.redhat.com/errata/RHSA-2026:2769


Note You need to log in before you can comment on or make changes to this bug.