
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68142 is a Regular Expression Denial of Service (ReDOS) vulnerability in PyMdown Extensions, a set of extensions for the Python-Markdown project. The flaw exists in the figure caption extension (pymdownx.blocks.caption) and affects all versions prior to 10.16.1. It was published on December 15–16, 2025, after being initially reported through the project's normal issue tracker rather than the security disclosure process. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 2.7 (Low) (GitHub Advisory, Security Advisory).
The root cause is an inefficient regular expression pattern (CWE-1333) in pymdownx/blocks/caption.py. The vulnerable pattern RE_FIG_NUM = re.compile(r'^(\^)?([1-9][0-9]*(?:.[1-9][0-9]*)*)(?= |$)') uses an unescaped . (matching any character) instead of the intended \. (literal dot), creating ambiguity that causes catastrophic backtracking when the regex engine processes certain inputs. An attacker can exploit this by submitting a crafted string — such as a long sequence of digits followed by a non-matching character (e.g., '1' * N + 'a') — to any system that processes user-supplied content through the pymdownx.blocks.caption extension. No authentication or special privileges are required. A public PoC demonstrating exponential execution time growth was provided by researcher @ShangzhiXu and is included in the advisory (Security Advisory, Fix Commit).
Successful exploitation causes excessive CPU consumption on the server processing the malicious input, resulting in a denial of service condition. The impact is limited to availability — there is no confidentiality or integrity impact, and subsequent systems are not affected. Systems most at risk are those that accept unchecked user-supplied markdown content and render it using the pymdownx.blocks.caption extension without processing timeouts or input size limits (GitHub Advisory).
There is no evidence of active in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A public proof-of-concept demonstrating the ReDOS behavior is included in the official security advisory. The EPSS score is approximately 0.04–0.08%, indicating a low probability of exploitation in the near term (GitHub Advisory, Feedly).
pymdownx.blocks.caption extension enabled.'1' * 500 + 'a'. This exploits the ambiguous . in the regex pattern to trigger catastrophic backtracking.^[1-9][0-9]{50,}[^0-9\s] submitted to markdown-processing endpoints.Upgrade PyMdown Extensions to version 10.16.1 or later, which fixes the regex pattern by replacing the unescaped . with \. to match only literal dots (Fix Commit). As a temporary workaround, disable the pymdownx.blocks.caption extension in your configuration until an upgrade is possible. Additionally, implement processing timeouts, input size limits, and input validation for all user-supplied content to reduce exposure (Security Advisory).
The vulnerability was initially reported through the project's public issue tracker (#2716) rather than the security disclosure process, which the maintainer acknowledged and committed to improving in the future. The fix was merged promptly via PR #2717. Coverage has been limited to automated vulnerability feeds and aggregators, with no significant broader media or researcher commentary beyond the advisory itself (Security Advisory).
Fix availability across major Linux distributions and their releases.
bookworm
pymdown-extensions
sid
pymdown-extensions: 10.13-4
trixie
pymdown-extensions: 10.13-1+deb13u1
devel
pymdown-extensions
noble
pymdown-extensions
noble (esm-apps)
pymdown-extensions
resolute
pymdown-extensions
resolute (esm-apps)
pymdown-extensions
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."