Threat Advisory

pymdown-extensions Critical Security Vulnerability Identified

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity regular expression denial-of-service (ReDoS) vulnerability, tracked as CVE-2026-67422, affects pymdown-extensions versions 11.0.0 and earlier. Four inline processors—caret, tilde, betterem, and magiclink—contain regular expressions susceptible to exponential backtracking, allowing an attacker to submit a specially crafted Markdown line shorter than 50 bytes that can cause unbounded CPU consumption and potentially disrupt the rendering service. The vulnerability is fixed in pymdown-extensions version 11.0.1.

RECOMMENDATION:

We recommend you to update pymdown-extensions to version 11.0.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity regular expression denial-of-service (ReDoS) vulnerability, tracked as CVE-2026-67422, affects pymdown-extensions versions 11.0.0 and earlier. Four inline processors—caret, tilde, betterem, and magiclink—contain regular expressions susceptible to exponential backtracking, allowing an attacker to submit a specially crafted Markdown line shorter than 50 bytes that can cause unbounded CPU consumption and potentially disrupt the rendering service. The vulnerability is fixed in pymdown-extensions version 11.0.1.

RECOMMENDATION:

We recommend you to update pymdown-extensions to version 11.0.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu