HIGH · 7.5

CVE-2022-34749

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named cat...

Vulnerability Description

In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Mistune ProjectMistune<= 2.0.2
FedoraprojectFedora37

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-34749?

CVE-2022-34749 is a vulnerability with a CVSS score of 7.5 (HIGH). In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named cat...

How severe is CVE-2022-34749?

CVE-2022-34749 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-34749?

Check the references section above for vendor advisories and patch information. Affected products include: Mistune Project Mistune, Fedoraproject Fedora.