Source: pymdown-extensions Version: 10.13-3 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Control: found -1 10.13-1
Hi, The following vulnerability was published for pymdown-extensions. CVE-2025-68142[0]: | PyMdown Extensions is a set of extensions for the `Python-Markdown` | markdown project. Versions prior to 10.16.1 have a ReDOS bug found | within the figure caption extension (`pymdownx.blocks.caption`). In | systems that take unchecked user content, this could cause long | hanges when processing the data if a malicious payload was crafted. | This issue is patched in Release 10.16.1. As a workaround, those who | process unknown user content without timeouts or other safeguards in | place to prevent really large, malicious content being aimed at | systems may avoid the use of `pymdownx.blocks.caption` until they're | able to upgrade. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2025-68142 https://www.cve.org/CVERecord?id=CVE-2025-68142 [1] https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-r6h4-mm7h-8pmq [2] https://github.com/facelessuser/pymdown-extensions/commit/b50d15a56850ed1408a284bba81cc019c6bd72e8 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

