CVE-2025-46656: Matthewwithanm Markdownify

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.

Affected products

Published 2025-04-26. Last modified 2026-06-17.