PT-2026-23450 · Unknown+3 · Python-Markdown+3

CVE-2025-69534

·

Published

2025-05-10

·

Updated

2026-08-25

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions Python-Markdown versions prior to 3.8.1
Description A flaw exists in Python-Markdown version 3.8 where improperly formed HTML-like sequences can trigger an unhandled AssertionError within the html.parser.HTMLParser during Markdown processing. Because Python-Markdown does not handle this exception, applications processing attacker-controlled Markdown may experience crashes. This can lead to a remote, unauthenticated Denial of Service in various systems, including web applications, documentation systems, and CI/CD pipelines that render untrusted Markdown. The issue may also result in Information Disclosure through uncaught exceptions.
Recommendations Update to Python-Markdown version 3.8.1 or later.

Exploit

Fix

DoS

Resource Exhaustion

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19155
ALSA-2026:19366
BDU:2026-11381
CVE-2025-69534
ECHO-3E8B-D85E-69BA
GHSA-5WMX-573V-2QWQ
OESA-2026-1787
OESA-2026-1788
OESA-2026-1789
OESA-2026-1790
PYSEC-2026-89
RHSA-2026:13508
RHSA-2026:13512
RHSA-2026:14835
RHSA-2026:14873
RHSA-2026:14874
RHSA-2026:19155
RHSA-2026:19366
RHSA-2026:20674
RHSA-2026:20676
RHSA-2026:20677
SUSE-SU-2026:0846-1
USN-8509-1
USN-8614-1

Affected Products

Linuxmint
Python-Markdown
Rocky Linux
Ubuntu