{"schema_version":"1.7.2","id":"OESA-2026-1790","modified":"2026-08-06T11:10:48Z","published":"2026-04-03T11:10:48Z","upstream":["CVE-2025-69534"],"summary":"python-markdown security update","details":"This is a Python implementation of John Gruber’s Markdown. It is almost completely compliant with the reference implementation, though there are a few known issues.\r\n\r\nSecurity Fix(es):\n\nPython-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.(CVE-2025-69534)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP3","name":"python-markdown","purl":"pkg:rpm/openEuler/python-markdown&distro=openEuler-24.03-LTS-SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.7-2.oe2403sp3"}]}],"ecosystem_specific":{"noarch":["python3-markdown-3.7-2.oe2403sp3.noarch.rpm"],"src":["python-markdown-3.7-2.oe2403sp3.src.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1790"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69534"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}],"database_specific":{"severity":"High"}}
