CVE-2025-69534

EUVD-2025-208312
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 44.81%
Affected Products (NVD)
VendorProductVersion
python-markdownmarkdown
3.8
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
0:3.10.2-1.el8ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
0:3.10.2-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
0:4.7.11-2.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
0:3.10.2-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10
0:3.5.1-6.el10_2.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:3.5.1-6.el10_0.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:3.3.4-4.el9_8.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support
0:3.3.4-4.el9_4.2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:3.3.4-4.el9_6.2 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.16 for RHEL 8
0:3.8.2-1.el8pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.16 for RHEL 9
0:3.8.2-1.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.17 for RHEL 9
0:3.8.2-1.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.18 for RHEL 9
0:3.8.2-1.el9pc ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.8
1776784286 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1777903262 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1776768939 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1776243287 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1776272253 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
pypy3
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
python2.7
bullseye
vulnerable
python3.11
bookworm
no-dsa
bookworm (security)
vulnerable
python3.13
forky
3.13.15-1
fixed
sid
3.13.15-1
fixed
trixie
3.13.5-2+deb13u3
fixed
python3.14
forky
3.14.6-1
fixed
sid
3.14.7-1
fixed
python3.9
bullseye
postponed
bullseye (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pypy3
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
python2.7
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
resolute
dne
trusty
needs-triage
xenial
Fixed 2.7.12-1ubuntu0~16.04.18+esm21
released
python3.5
jammy
dne
noble
dne
questing
dne
resolute
dne
trusty
needs-triage
xenial
Fixed 3.5.2-2ubuntu0~16.04.13+esm24
released
python3.10
jammy
Fixed 3.10.12-1~22.04.16
released
noble
dne
questing
dne
resolute
dne
python3.12
jammy
dne
noble
Fixed 3.12.3-1ubuntu0.15
released
questing
dne
resolute
dne
python3.13
jammy
dne
noble
dne
questing
not-affected
resolute
dne
python3.14
jammy
dne
noble
dne
questing
not-affected
resolute
not-affected
python3.11
jammy
needs-triage
noble
dne
questing
dne
resolute
dne
python3.4
jammy
dne
noble
dne
questing
dne
resolute
dne
trusty
needs-triage
python3.6
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
python3.7
bionic
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
python3.8
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
python3.9
focal
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
python3-markdown
RHEL 9
0:3.3.4-4.el9_8.2
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python3-markdown
Amazon Linux 2023
0:3.3.4-2.amzn2023.0.4
fixed