Executive brief
Python-Markdown is a popular library used to convert Markdown text into HTML for display in web applications, documentation sites, and automated pipelines. A vulnerability in version 3.8 allows an attacker to crash any application that processes untrusted Markdown by providing specifically malformed text. This can lead to service outages (Denial of Service) and potentially expose internal system information through error messages.
Technical details
A Reachable Assertion vulnerability (CWE-617) exists in Python-Markdown version 3.8. When the library processes malformed HTML-like sequences (specifically those starting with '<![') while the 'extra' extension is enabled, it triggers an unhandled AssertionError or 'expected name token' exception from the standard library's html.parser.HTMLParser. Because the library does not catch these exceptions, the entire application process may crash. This allows a remote, unauthenticated attacker to cause a Denial of Service by submitting malicious Markdown content. The issue is a result of a bug in the Python standard library (cpython#77057) for which Python-Markdown has implemented a workaround in version 3.8.1.
Affected products
- Python-Markdown Project Python-Markdown 3.8
Timeline
- 2025-06-18: disclosed: Issue reported on GitHub and version 3.8.1 released as a fix
- 2026-03-05: advisory: NVD published CVE-2025-69534
References
- https://github.com/Python-Markdown/markdown
- https://github.com/Python-Markdown/markdown/actions/runs/15736122892
- https://github.com/Python-Markdown/markdown/issues/1534
- http://www.openwall.com/lists/oss-security/2026/03/06/4
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/errata/RHSA-2026:13508
- https://access.redhat.com/errata/RHSA-2026:13512