CVE-2022-34749

Name
CVE-2022-34749
Description
In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/lepture/mistune/commit/a6d43215132fe4f3d93f8d7e90ba83b16a0838b2
MISC https://github.com/lepture/mistune/releases
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TQHXITQ2DSBYOILKHXBSBB7PFBPZHF63/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQHXITQ2DSBYOILKHXBSBB7PFBPZHF63/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:mistune_project:mistune:*:*:*:*:*:*:*:* mistune >= None <= 2.0.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status