Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-markdown | Jul 7, 2026 | May 19, 2026 |
| Debian | — | Upgrade python3.13 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | Upgrade automation-gateway-proxyUpgrade python3.12-django-ansible-base+resource_registryUpgrade python3.12-galaxy-importerUpgrade python3.12-pyjwt+cryptoUpgrade python3.12-pulpcoreUpgrade python3.12-pytokensUpgrade automation-controller-venv-towerUpgrade automation-gateway-proxy-debugsourceUpgrade python3-pathspecUpgrade automation-hubUpgrade python3.12-blackUpgrade automation-gatewayUpgrade automation-gateway-proxy-serverUpgrade ansible-testUpgrade ansible-lintUpgrade automation-controllerUpgrade automation-controller-uiUpgrade automation-eda-controller-base-servicesUpgrade python3.12-pyasn1-modulesUpgrade python3-blackUpgrade python3.12-cryptographyUpgrade automation-eda-controller-event-stream-servicesUpgrade python3.12-pyasn1Upgrade python3.12-galaxy-ngUpgrade receptorctlUpgrade python3.12-pysequoiaUpgrade python3.12-django-ansible-base+activitystreamUpgrade python3.12-pyOpenSSLUpgrade python3.12-cryptography-debuginfoUpgrade python3.12-pytokens-debuginfoUpgrade automation-eda-controller-worker-servicesUpgrade python3.12-django-ansible-base+rest_filtersUpgrade automation-controller-serverUpgrade python3-pytokens-debuginfoUpgrade automation-controller-cliUpgrade automation-eda-controllerUpgrade python3.12-pyjwtUpgrade ansible-coreUpgrade python3-wheel-wheelUpgrade python3.12-pathspecUpgrade python3.12-markdownUpgrade python3-pytokensUpgrade python3.12-django-ansible-base+feature_flagsUpgrade automation-gateway-proxy-server-debuginfoUpgrade python3.12-django-ansible-base+channel_authUpgrade python3.12-django-ansible-base+api_documentationUpgrade python3.12-cffi-debuginfoUpgrade python3.12-pulp-containerUpgrade receptor-debugsourceUpgrade python3.12-django-ansible-base+rbacUpgrade yamllintUpgrade python-pytokens-debugsourceUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade receptorUpgrade python3.12-pysequoia-debugsourceUpgrade python3.12-cryptography-debugsourceUpgrade automation-eda-controller-baseUpgrade receptor-debuginfoUpgrade python3.12-django-ansible-base+authenticationUpgrade python3-markdownUpgrade python3.12-pysequoia-debuginfoUpgrade python3.12-django-ansible-base+redis_clientUpgrade automation-gateway-configUpgrade python3.12-dynaconfUpgrade python3.12-django-ansible-baseUpgrade python3.12-cffi-debugsourceUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade automation-gateway-serverUpgrade python3.12-cffiUpgrade automation-platform-uiUpgrade python3.12-pytokens-debugsourceUpgrade python3.12-jwcrypto | May 6, 2026 | Mar 5, 2026 |
| Ubuntu | — | Upgrade libpython3.5-stdlib (Ubuntu Pro)Upgrade python3.10Upgrade libpython3.10Upgrade libpython2.7-minimal (Ubuntu Pro)Upgrade python3.12Upgrade libpython2.7-stdlib (Ubuntu Pro)Upgrade libpython3.12t64 | Jul 6, 2026 | Mar 5, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub