Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r6h4-mm7h-8pmq | PyMdown Extensions has a ReDOS bug in its Figure Capture extension |
Tue, 03 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Facelessuser
Facelessuser pymdown Extensions |
|
| CPEs | cpe:2.3:a:facelessuser:pymdown_extensions:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Facelessuser
Facelessuser pymdown Extensions |
Wed, 17 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 16 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption extension (`pymdownx.blocks.caption`). In systems that take unchecked user content, this could cause long hanges when processing the data if a malicious payload was crafted. This issue is patched in Release 10.16.1. As a workaround, those who process unknown user content without timeouts or other safeguards in place to prevent really large, malicious content being aimed at systems may avoid the use of `pymdownx.blocks.caption` until they're able to upgrade. | |
| Title | PyMdown Extensions has ReDOS bug in Figure Capture extension | |
| Weaknesses | CWE-1333 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-17T18:51:08.232Z
Reserved: 2025-12-15T18:15:08.404Z
Link: CVE-2025-68142
Updated: 2025-12-17T14:53:31.700Z
Status : Analyzed
Published: 2025-12-16T18:16:16.693
Modified: 2026-02-03T18:56:25.143
Link: CVE-2025-68142
OpenCVE Enrichment
No data.
Github GHSA