REDHAT-BUG-2444839: High severity pypi/markdown vulnerability
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Python-Markdownto a version that resolves this vulnerability.Fixed in 3.8.1
Event History
Frequently Asked Questions
Which deployments are exposed?
Any application or service that parses Markdown supplied by untrusted users is exposed. Examples include web applications, documentation systems, and CI/CD pipelines that render attacker-controlled Markdown.
What does an attacker need to exploit this issue?
An attacker only needs to provide Markdown containing malformed HTML-like sequences to a reachable Markdown-parsing workflow. The described attack is remote and unauthenticated.
Which version should be remediated?
Python-Markdown version 3.8 is identified as affected. The vendor fixed the issue in version 3.8.1.
What is the operational impact of successful exploitation?
Malformed input can trigger an unhandled AssertionError and crash the Markdown-parsing application, causing denial of service. Uncaught exceptions may also expose information.