← Vulnerability feed

Vulnerability record · CVE-2026-44899 · published 26 May 2026

CVE-2026-44899: Mistune project mistune cross-site scripting vulnerability

Mistune Project · Mistune

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^\d+(?:\.\d*)?"). When the validated value is not a plain integer, render_block_image() inserts it directly into a style="width:...;" or style="height:...;" attribute. Because the value was accepted by the prefix-only regex, any CSS after the leading digits reaches the style= attribute verbatim and without escaping. This vulnerability is fixed in 3.2.1.

6.1 CVSS 3.1 Medium EPSS 0.27% · top 82.5% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
24 Jul 2026Last modified by NVD

Description

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^\d+(?:\.\d*)?"). When the validated value is not a plain integer, render_block_image() inserts it directly into a style="width:...;" or style="height:...;" attribute. Because the value was accepted by the prefix-only regex, any CSS after the leading digits reaches the style= attribute verbatim and without escaping. This vulnerability is fixed in 3.2.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-44899 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-59925Mistune project mistune inefficient regular expression (redos) vulnerabilityMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emph…EPSS 0.64%7.5CVE-2026-59928Mistune project mistune inefficient regular expression (redos) vulnerabilityMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-li…EPSS 0.65%7.5CVE-2026-59922Mistune project mistune inefficient regular expression (redos) vulnerabilityMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a ch…EPSS 0.64%7.5CVE-2022-34749Mistune project mistune inefficient regular expression (redos) vulnerabilityIn mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on cert…EPSS 1.5%6.1CVE-2026-59929Mistune project mistune cross-site scripting vulnerabilityMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only java…EPSS 0.34%6.1CVE-2026-59923Mistune project mistune cross-site scripting vulnerabilityMistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URI…EPSS 0.35%6.1CVE-2026-44897Mistune project mistune cross-site scripting vulnerabilityMistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concaten…EPSS 0.27%6.1CVE-2026-44898Mistune project mistune cross-site scripting vulnerabilityMistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2026-44899), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.