CVE-2025-69534Disclosure(python-markdown / markdown)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch python-markdown markdown systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-617

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • markdown

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-03-09)
  • 7 total mentions across 3 days

Affected systems

Products
markdown

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-05: 1Mentions · 2026-03-08: 2Mentions · 2026-03-09: 4Patch / Workaround · 2026-03-09: 3Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 2Technical Details · 2026-03-09: 203-0503-0803-09
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-082
Disclosure2
2026-03-094
Disclosure1Patch3
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2025-69534: Python-Markdown: Malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing https://www.openwall.com/lists/oss-security/2026/03/06/4 remote DoS in any application parsing untrusted Markdown, and can lead to Information Disclosure

    Post summary

    CVE-2025-69534 involves a flaw in Python‑Markdown’s HTML parser that can cause unhandled assertion errors, leading to denial of service and information disclosure when processing untrusted Markdown. No exploitation evidence, patch, or PoC is referenced.

    00030376
    4.4K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical DoS vulnerability patched in openSUSE 15.6 (CVE-2025-69534). The flaw in python-Markdown lets remote attackers crash apps via incomplete HTML markup. Read more: 👉 https://tinyurl.com/53beckja #openSUSE #Security https://t.co/CPWGl76yoy

    Post summary

    The tweet announces that CVE‑2025‑69534, a critical DoS vulnerability in python‑Markdown that crashes apps via incomplete HTML markup, has been patched in openSUSE 15.6.

    0001080
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69534 Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during M… https://www.cve.org/CVERecord?id=CVE-2025-69534

    Post summary

    The text announces a vulnerability in Python-Markdown 3.8 that triggers an unhandled AssertionError when parsing malformed HTML-like content, with no PoC, exploit, or patch details provided.

    00010274
    56.6K followersView on X
  • ThreatCluster@threatcluster
    Patch

    openSUSE Leap 15.6 patches critical python-Markdown bug (CVE-2025-69534) that can crash apps parsing untrusted Markdown. Users should update immediately via YaST online_update or zypper patch. https://threatcluster.io/cluster/critical-crash-risk-in-opensuse-leap-156-due-to-python-markd-e686ec80

    Post summary

    The post announces a critical patch for CVE-2025-69534 in openSUSE Leap 15.6 and urges users to update via YaST or zypper, with no evidence of active exploitation or detailed technical information.

    0000068
    100 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads-up, #openSUSE community! A new security patch for Leap 15.6 is out, addressing CVE-2025-69534 in python-Markdown Read more: Read more: 👉 https://tinyurl.com/3cwkrbhf #Security https://t.co/SJnbVRc89E

    Post summary

    The tweet announces a new patch for openSUSE Leap 15.6 that addresses CVE‑2025‑69534, without providing exploitation details or vulnerability specifics.

    0000062
    1.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-69534 Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during M… https://www.cve.org/CVERecord?id=CVE-2025-69534 ----- Traducción: CVE-2025-69534 Pyt… http://infoflow.cloud`

    Post summary

    The tweet reports CVE‑2025‑69534, a flaw in Python‑Markdown 3.8 that triggers an unhandled AssertionError when parsing malformed HTML‑like input, offering technical details but no PoC, exploit, patch, or evidence of active exploitation.

    0000086
    56 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69534 Unauthenticated Denial of Service in Python-Markdown 3.8 via HTML Parsing Exception https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69534

    Post summary

    The text announces CVE‑2025‑69534 as an unauthenticated denial‑of‑service vulnerability in Python‑Markdown 3.8, providing basic technical details but no PoC, exploit code, or patch information.

    0000050
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppython-markdownmarkdown3.8python-

Explore more