# CVE-2025-69534

## Summary

- **CVE ID:** CVE-2025-69534
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
- **CWE:** N/A
- **Published:** Mar 5, 2026
- **Last Modified:** Sep 14, 2026

## Description

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](https://github.com/Python-Markdown/markdown/issues/1534)
- [CNA](https://github.com/Python-Markdown/markdown)
- [CNA](https://github.com/Python-Markdown/markdown/actions/runs/15736122892)
- [CVE](http://www.openwall.com/lists/oss-security/2026/03/06/4)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2025-69534)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2444839)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:13512)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:14874)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:13508)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:14873)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:14835)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:20677)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:19155)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:20674)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:20676)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:19366)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:9742)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:13826)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:10184)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.57%
- **EPSS Percentile:** 45.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._