CVE-2025-69534
published 2026-03-05CVE-2025-69534: Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
43.2th percentile
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | < python3.13 3.13.4-1 (forky) | python3.13 3.13.4-1 (forky) |
| debian | python2.7 | < python3.13 3.13.4-1 (forky) | python3.13 3.13.4-1 (forky) |
| debian | python3.11 | < python3.13 3.13.4-1 (forky) | python3.13 3.13.4-1 (forky) |
| debian | python3.13 | < python3.13 3.13.4-1 (forky) | python3.13 3.13.4-1 (forky) |
| debian | python3.14 | < python3.13 3.13.4-1 (forky) | python3.13 3.13.4-1 (forky) |
| debian | python3.9 | < python3.13 3.13.4-1 (forky) | python3.13 3.13.4-1 (forky) |
| python-markdown | markdown | — | — |
| python-markdown | markdown | >= 0 < 3.8.1 | 3.8.1 |
| ubuntu | python3.10 | — | — |
| ubuntu | python3.12 | — | — |
| ubuntu | python3.14 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Python-Markdown has an Uncaught Exception
osv·2026-03-05
CVE-2025-69534 [MEDIUM] Python-Markdown has an Uncaught Exception
Python-Markdown has an Uncaught Exception
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
OSV
CVE-2025-69534: Python-Markdown version 3
osv·2026-03-05·CVSS 7.5
CVE-2025-69534 [HIGH] CVE-2025-69534: Python-Markdown version 3
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
GHSA
Python-Markdown has an Uncaught Exception
ghsa·2026-03-05
CVE-2025-69534 [MEDIUM] CWE-248 Python-Markdown has an Uncaught Exception
Python-Markdown has an Uncaught Exception
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 3.3
CVE-2026-9669 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly normalized paths in the tarfile
module. An attacker could possibly use this issue to bypass path
restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2025-13462)
It was discovered that Python's HTMLParser incorrectly handled certain
malformed HTML input. An attacker could possibly use this issue to cause
Python to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)
It was discovered that Python's email module incorrectly quoted newlines
in headers. An attacker could possibly use this issue to inject arbitrary
email headers. This issue only affected Ubuntu 22.04 L
Red Hat
python-markdown: denial of service via malformed HTML-like sequences
vendor_redhat·2026-03-05·CVSS 7.5
CVE-2025-69534 [HIGH] CWE-617 python-markdown: denial of service via malformed HTML-like sequences
python-markdown: denial of service via malformed HTML-like sequences
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
A flaw was found in Python
Debian
CVE-2025-69534: pypy3 - Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like se...
vendor_debian·2025·CVSS 7.5
CVE-2025-69534 [HIGH] CVE-2025-69534: pypy3 - Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like se...
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-69534 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-69534 [HIGH] CVE-2025-69534 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69534 :
Python vulnerability analysis and mitigation
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
Source : NVD
## 7.5
Score
Bugzilla
CVE-2025-69534 python-markdown: denial of service via malformed HTML-like sequences
bugzilla·2026-03-05·CVSS 7.5
CVE-2025-69534 [HIGH] CVE-2025-69534 python-markdown: denial of service via malformed HTML-like sequences
CVE-2025-69534 python-markdown: denial of service via malformed HTML-like sequences
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
Discussion
https://github.com/Python-Markdown/markdownhttps://github.com/Python-Markdown/markdown/actions/runs/15736122892https://github.com/Python-Markdown/markdown/issues/1534http://www.openwall.com/lists/oss-security/2026/03/06/4https://access.redhat.com/errata/RHSA-2026:10184https://access.redhat.com/errata/RHSA-2026:13508https://access.redhat.com/errata/RHSA-2026:13512https://access.redhat.com/errata/RHSA-2026:13826https://access.redhat.com/errata/RHSA-2026:14835https://access.redhat.com/errata/RHSA-2026:14873https://access.redhat.com/errata/RHSA-2026:14874https://access.redhat.com/errata/RHSA-2026:19155https://access.redhat.com/errata/RHSA-2026:19366https://access.redhat.com/errata/RHSA-2026:20674https://access.redhat.com/errata/RHSA-2026:20676https://access.redhat.com/errata/RHSA-2026:20677https://access.redhat.com/errata/RHSA-2026:9742https://access.redhat.com/security/cve/CVE-2025-69534https://bugzilla.redhat.com/show_bug.cgi?id=2444839https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json
2026-03-05
Published