CVE-2025-69534
CVE-2025-69534
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.5EPSS 0.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
05 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
n/a · n/aReferencias
https://access.redhat.com/errata/RHSA-2026:10184https://access.redhat.com/errata/RHSA-2026:13508https://access.redhat.com/errata/RHSA-2026:13512https://access.redhat.com/errata/RHSA-2026:13826https://access.redhat.com/errata/RHSA-2026:14835https://access.redhat.com/errata/RHSA-2026:14873https://access.redhat.com/errata/RHSA-2026:14874https://access.redhat.com/errata/RHSA-2026:19155https://access.redhat.com/errata/RHSA-2026:19366https://access.redhat.com/errata/RHSA-2026:20674https://access.redhat.com/errata/RHSA-2026:20676https://access.redhat.com/errata/RHSA-2026:20677