THREAT OPS › Threat News › [GHSA] GHSA-gm37-52c6-37mw (high) — pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
[GHSA] GHSA-gm37-52c6-37mw (high) — pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
GHSA-gm37-52c6-37mw Severity: high CVE: CVE-2026-67422
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
### Summary
Four inline processors in pymdown-extensions contain regular expressions with exponential backtracking. A single untrusted Markdown line under 50 bytes drives `markdown.markdown()` into unbounded CPU on the rendering thr
Indicators of compromise
- CVE-2026-67422cve
- CVE-2025-68142cve
- http://aurl
Original source: https://github.com/advisories/GHSA-gm37-52c6-37mw