LOW2.9
PYSEC-2026-1604
markdownify allows large headline prefixes such as <h9999999>, which causes memory consumption
Quick fix
PYSEC-2026-1604 — markdownify: upgrade to the fixed version with the command below.
pip install --upgrade 'markdownify>=0.14.1'Details
python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-46656[ADVISORY]
- https://github.com/matthewwithanm/python-markdownify/issues/143[WEB]
- https://github.com/matthewwithanm/python-markdownify/commit/959561879693bf4a576f99c6733b50b01186aa08[WEB]
- https://github.com/matthewwithanm/python-markdownify[PACKAGE]
- https://github.com/matthewwithanm/python-markdownify/compare/0.14.0...0.14.1[WEB]
- https://pypi.org/project/markdownify[PACKAGE]
- https://github.com/advisories/GHSA-7mpr-5m44-h73r[ADVISORY]