Skip to content
VulniPulse
Medium6.5Red Hat Linux

Medium [CVE-2026-59928] Denial of Service via crafted Markdown document with reference-link definitions

This medium-severity Red Hat Linux advisory covers CVE-2026-59928 affecting Migration Toolkit for Applications 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4.

CVE-2026-59928 Published Jul 8, 2026Updated by vendor Jul 8, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service through CPU exhaustion.

This issue is fixed in version 3.3.0. A remote attacker could exploit this vulnerability by providing a specially crafted Markdown document containing numerous repeated or distinct reference-link definitions.

This can lead to excessive processing, causing CPU exhaustion and a denial of service (DoS) for the affected system. This triggers excessive CPU consumption during parsing, which may render affected applications unresponsive and result in a denial of service.

Red Hat uses PR:L because delivering the crafted Markdown document document to Mistune will require authenticated access in affected products, platform login/RBAC prevents unauthenticated remote submission in default deployments. The upstream PR:N score assumes any Internet-facing app parsing untrusted Markdown without authentication.

Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-606.

Affected Red Hat products: Migration Toolkit for Applications 8; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat Satellite 6.

Affected versions
  • < 3.3.0

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Fixed versions
  • 3.3.0

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, avoid processing untrusted Markdown documents with affected Red Hat products. Restricting the input sources to trusted content can reduce the risk of a denial of service attack.

Official advisory · high-confidence parse· fetched 10 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.