
🚨High - pymdown-extensions ReDoS via Inline Processor Regex Backtracking (CVE-2026-67422) pymdown-extensions inline processors (caret, tilde, betterem, magiclink) use inefficient regex patterns that catastrophically backtrack on crafted short Markdown lines. If an attacker can submit untrusted Markdown, they can drive unbounded CPU usage and cause a DoS. Instances not processing attacker-controlled Markdown aren’t impacted. 👉Affected: pymdown-extensions < 11.0.1 | Upgrade to 11.0.1
Post summary
A high‑severity regex backtracking vulnerability (CVE‑2026‑67422) in pymdown‑extensions can cause DoS, mitigated by upgrading to version 11.0.1.
