cbcvebase.
CVE-2025-69534
published 2026-03-05

CVE-2025-69534: Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
43.2th percentile
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianpypy3< python3.13 3.13.4-1 (forky)python3.13 3.13.4-1 (forky)
debianpython2.7< python3.13 3.13.4-1 (forky)python3.13 3.13.4-1 (forky)
debianpython3.11< python3.13 3.13.4-1 (forky)python3.13 3.13.4-1 (forky)
debianpython3.13< python3.13 3.13.4-1 (forky)python3.13 3.13.4-1 (forky)
debianpython3.14< python3.13 3.13.4-1 (forky)python3.13 3.13.4-1 (forky)
debianpython3.9< python3.13 3.13.4-1 (forky)python3.13 3.13.4-1 (forky)
python-markdownmarkdown
python-markdownmarkdown>= 0 < 3.8.13.8.1
ubuntupython3.10
ubuntupython3.12
ubuntupython3.14

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.