CVE-2025-68142: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-68142 is a Regular Expression Denial of Service (ReDOS) vulnerability in PyMdown Extensions, a set of extensions for the Python-Markdown project. The flaw exists in the figure caption extension (pymdownx.blocks.caption) and affects all versions prior to 10.16.1. It was published on December 15–16, 2025, after being initially reported through the project's normal issue tracker rather than the security disclosure process. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 2.7 (Low) (GitHub Advisory, Security Advisory).

Technical details

The root cause is an inefficient regular expression pattern (CWE-1333) in pymdownx/blocks/caption.py. The vulnerable pattern RE_FIG_NUM = re.compile(r'^(\^)?([1-9][0-9]*(?:.[1-9][0-9]*)*)(?= |$)') uses an unescaped . (matching any character) instead of the intended \. (literal dot), creating ambiguity that causes catastrophic backtracking when the regex engine processes certain inputs. An attacker can exploit this by submitting a crafted string — such as a long sequence of digits followed by a non-matching character (e.g., '1' * N + 'a') — to any system that processes user-supplied content through the pymdownx.blocks.caption extension. No authentication or special privileges are required. A public PoC demonstrating exponential execution time growth was provided by researcher @ShangzhiXu and is included in the advisory (Security Advisory, Fix Commit).

Impact

Successful exploitation causes excessive CPU consumption on the server processing the malicious input, resulting in a denial of service condition. The impact is limited to availability — there is no confidentiality or integrity impact, and subsequent systems are not affected. Systems most at risk are those that accept unchecked user-supplied markdown content and render it using the pymdownx.blocks.caption extension without processing timeouts or input size limits (GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A public proof-of-concept demonstrating the ReDOS behavior is included in the official security advisory. The EPSS score is approximately 0.04–0.08%, indicating a low probability of exploitation in the near term (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify target: Locate a web application or service that accepts user-supplied markdown content and renders it using PyMdown Extensions (versions < 10.16.1) with the pymdownx.blocks.caption extension enabled.
  2. Craft malicious payload: Construct a string consisting of a long sequence of digit characters followed by a non-matching character, such as '1' * 500 + 'a'. This exploits the ambiguous . in the regex pattern to trigger catastrophic backtracking.
  3. Submit payload: Submit the crafted string as user content (e.g., via a comment field, document editor, or API endpoint) that will be processed by the vulnerable extension.
  4. Observe denial of service: The regex engine enters exponential backtracking, consuming excessive CPU cycles and causing the processing thread or worker to hang, degrading or denying service to other users (Security Advisory).

Indicators of compromise

  • Logs: Unusually long processing times or timeouts logged for markdown rendering requests; repeated requests containing long numeric strings followed by non-numeric characters in user-submitted content fields.
  • Process: Sustained high CPU utilization on the application server process handling markdown rendering, particularly spikes correlated with specific user input submissions.
  • Network: High volume of requests containing patterns matching ^[1-9][0-9]{50,}[^0-9\s] submitted to markdown-processing endpoints.

Mitigation and workarounds

Upgrade PyMdown Extensions to version 10.16.1 or later, which fixes the regex pattern by replacing the unescaped . with \. to match only literal dots (Fix Commit). As a temporary workaround, disable the pymdownx.blocks.caption extension in your configuration until an upgrade is possible. Additionally, implement processing timeouts, input size limits, and input validation for all user-supplied content to reduce exposure (Security Advisory).

Community reactions

The vulnerability was initially reported through the project's public issue tracker (#2716) rather than the security disclosure process, which the maintainer acknowledged and committed to improving in the future. The fix was merged promptly via PR #2717. Coverage has been limited to automated vulnerability feeds and aggregators, with no significant broader media or researcher commentary beyond the advisory itself (Security Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pymdown-extensions

Fixed

sid

pymdown-extensions: 10.13-4

Fixed

trixie

pymdown-extensions: 10.13-1+deb13u1

Fixed

Ubuntu

Unknown

devel

pymdown-extensions

Unknown

noble

pymdown-extensions

Unknown

noble (esm-apps)

pymdown-extensions

Unknown

resolute

pymdown-extensions

Unknown

resolute (esm-apps)

pymdown-extensions

Unknown

RHEL / CentOS

Affected

OpenShift

openshift4/ose-agent-installer-api-server-rhel9

Affected

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management