Bug 2444839 (CVE-2025-69534) - CVE-2025-69534 python-markdown: denial of service via malformed HTML-like sequences
Summary: CVE-2025-69534 python-markdown: denial of service via malformed HTML-like seq...
Keywords:
Status: NEW
Alias: CVE-2025-69534
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2444869
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-05 16:01 UTC by OSIDB Bzimport
Modified: 2026-05-07 17:56 UTC (History)
39 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:13508 0 None None None 2026-05-04 13:58:49 UTC
Red Hat Product Errata RHSA-2026:13512 0 None None None 2026-05-04 14:15:43 UTC
Red Hat Product Errata RHSA-2026:14873 0 None None None 2026-05-07 17:26:28 UTC
Red Hat Product Errata RHSA-2026:14874 0 None None None 2026-05-07 17:55:59 UTC

Description OSIDB Bzimport 2026-03-05 16:01:33 UTC
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.

Comment 3 errata-xmlrpc 2026-05-04 13:58:46 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 10
  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:13508 https://access.redhat.com/errata/RHSA-2026:13508

Comment 4 errata-xmlrpc 2026-05-04 14:15:40 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:13512 https://access.redhat.com/errata/RHSA-2026:13512

Comment 6 errata-xmlrpc 2026-05-07 17:26:25 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:14873 https://access.redhat.com/errata/RHSA-2026:14873

Comment 7 errata-xmlrpc 2026-05-07 17:55:55 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:14874 https://access.redhat.com/errata/RHSA-2026:14874


Note You need to log in before you can comment on or make changes to this bug.