First published: Sat Apr 26 2025(Updated: )
python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
markdownify | <0.14.1 | |
pip/markdownify | <0.14.1 | 0.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46656 has a moderate severity level due to its potential for high memory consumption.
To fix CVE-2025-46656, upgrade python-markdownify to version 0.14.1 or later.
Versions of python-markdownify before 0.14.1 are affected by CVE-2025-46656.
CVE-2025-46656 allows for extremely large headline prefixes, leading to excessive memory consumption.
The vendor for the affected software in CVE-2025-46656 is python-markdownify.