<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:49:07.558417+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2026-59927</id>
    <title>BREW-adr-viewer-CVE-2026-59927 — Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of servi…</title>
    <updated>2026-10-04T21:49:07.565549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: adr-viewer</p>
<p>## Summary</p>
<p>**Type:** Uncontrolled recursion via mutual include. The `Include` directive checks for direct self-reference (`a.md` cannot include `a.md`), but does not detect indirect cycles. Two markdown files that include each other (`a.md` → includes `b.md` → includes `a.md`) cause unbounded recursion until Python's stack limit fires `RecursionError`. The exception propagates out of the renderer and crashes the calling code.
**File:** `src/mistune/directives/include.py`, lines 33-37 (the self-include check is the only cycle-detection logic).
**Root cause:** the include logic only compares `os.path.abspath(dest) == os.path.abspath(source_file)`. There is no per-render set of "files already included" that would catch transitive cycles. When `a.md` includes `b.md`, the recursive `block.parse(new_state)` call uses `dest` (b.md) as the new `__file__`, which then includes `a.md` (passing the self-check, because the immediate parent file is `b.md`, not `a.md`), which then includes `b.md`, and so on. Each recursion level adds Python frames; the default stack limit of 1000 frames trips after ~7-10 cycle iterations and Python raises `RecursionError`. Since the directive does not catch the exception, it propagates out of `Markdown.parse()` and surfaces in the calling code, crashing the request.</p>
<p>## Affected Code</p>
<p>**File:** `src/mistune/directives/include.py`, lines 28-54.</p>
<p>```python
relpath = self.parse_title(m)
dest = os.path.join(os.path.dirname(source_file), relpath)
dest = os.pat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2026-59927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-334064</id>
    <title>EUVD-2026-334064</title>
    <updated>2026-10-04T21:49:07.565650+00:00</updated>
    <content>EUVD-2026-334064</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-334064"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59927</id>
    <title>fkie_cve-2026-59927</title>
    <updated>2026-10-04T21:49:07.565667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionError, and crash the rendering request. This issue is fixed in version 3.3.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8mpj-m6qm-5qr8</id>
    <title>GHSA-8mpj-m6qm-5qr8 — Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of servi…</title>
    <updated>2026-10-04T21:49:07.565691+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mistune</p>
<p>## Summary</p>
<p>**Type:** Uncontrolled recursion via mutual include. The `Include` directive checks for direct self-reference (`a.md` cannot include `a.md`), but does not detect indirect cycles. Two markdown files that include each other (`a.md` → includes `b.md` → includes `a.md`) cause unbounded recursion until Python's stack limit fires `RecursionError`. The exception propagates out of the renderer and crashes the calling code.
**File:** `src/mistune/directives/include.py`, lines 33-37 (the self-include check is the only cycle-detection logic).
**Root cause:** the include logic only compares `os.path.abspath(dest) == os.path.abspath(source_file)`. There is no per-render set of "files already included" that would catch transitive cycles. When `a.md` includes `b.md`, the recursive `block.parse(new_state)` call uses `dest` (b.md) as the new `__file__`, which then includes `a.md` (passing the self-check, because the immediate parent file is `b.md`, not `a.md`), which then includes `b.md`, and so on. Each recursion level adds Python frames; the default stack limit of 1000 frames trips after ~7-10 cycle iterations and Python raises `RecursionError`. Since the directive does not catch the exception, it propagates out of `Markdown.parse()` and surfaces in the calling code, crashing the request.</p>
<p>## Affected Code</p>
<p>**File:** `src/mistune/directives/include.py`, lines 28-54.</p>
<p>```python
relpath = self.parse_title(m)
dest = os.path.join(os.path.dirname(source_file), relpath)
dest = os.pat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8mpj-m6qm-5qr8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21339-1</id>
    <title>openSUSE-SU-2026:21339-1 — Security update for python-mistune</title>
    <updated>2026-10-04T21:49:07.565751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-mistune</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21339-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2215</id>
    <title>PYSEC-2026-2215</title>
    <updated>2026-10-04T21:49:07.565771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: mistune</p>
<p>Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionError, and crash the rendering request. This issue is fixed in version 3.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2215"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22655-1</id>
    <title>SUSE-SU-2026:22655-1 — Security update for python-mistune</title>
    <updated>2026-10-04T21:49:07.565789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-mistune</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22655-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59927</id>
    <title>UBUNTU-CVE-2026-59927</title>
    <updated>2026-10-04T21:49:07.565805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: mistune, Ubuntu:18.04:LTS: mistune, Ubuntu:20.04:LTS: mistune, Ubuntu:22.04:LTS: mistune, Ubuntu:24.04:LTS: mistune, Ubuntu:25.10: mistune, Ubuntu:26.04:LTS: mistune</p>
<p>Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionError, and crash the rendering request. This issue is fixed in version 3.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59927"/>
  </entry>
</feed>
