CVE-2025-46656

python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.
Configurations

Configuration 1 (hide)

cpe:2.3:a:matthewwithanm:markdownify:*:*:*:*:*:python:*:*

History

16 Oct 2025, 20:24

Type Values Removed Values Added
First Time Matthewwithanm
Matthewwithanm markdownify
References () https://github.com/matthewwithanm/python-markdownify/compare/0.14.0...0.14.1 - () https://github.com/matthewwithanm/python-markdownify/compare/0.14.0...0.14.1 - Patch
References () https://github.com/matthewwithanm/python-markdownify/issues/143 - () https://github.com/matthewwithanm/python-markdownify/issues/143 - Exploit
CPE cpe:2.3:a:matthewwithanm:markdownify:*:*:*:*:*:python:*:*

29 Apr 2025, 16:15

Type Values Removed Values Added
References () https://github.com/matthewwithanm/python-markdownify/issues/143 - () https://github.com/matthewwithanm/python-markdownify/issues/143 -
Summary
  • (es) La versión 0.14.1 de Python-markdownify (también conocida como markdownify) permite prefijos de encabezado largos, como , además de los prefijos a . Esto consume memoria.

26 Apr 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-26 22:15

Updated : 2025-10-16 20:24


NVD link : CVE-2025-46656

Mitre link : CVE-2025-46656

CVE.ORG link : CVE-2025-46656


JSON object : View

Products Affected

matthewwithanm

  • markdownify
CWE
CWE-1284

Improper Validation of Specified Quantity in Input