Debian Package Tracker
Register | Log in
Subscribe

pymdown-extensions

Extension pack for Python Markdown

Choose email to subscribe with

general
  • source: pymdown-extensions (main)
  • version: 11.0.1-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Alexandre Detiste [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 9.5-2
  • stable: 10.13-1+deb13u1
  • testing: 11.0.1-1
  • unstable: 11.0.1-1
versioned links
  • 9.5-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 10.13-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 11.0.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-pymdownx
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:01:37
    Last run: 2026-07-12T18:35:07.000Z
    Previous status: unknown

  • testing: pass (log)
    The tests ran in 0:01:37
    Last run: 2026-07-31T03:05:16.000Z
    Previous status: unknown

  • stable: pass (log)
    The tests ran in 0:00:49
    Last run: 2026-07-17T18:02:55.000Z
    Previous status: unknown

Created: 2026-07-12 Last update: 2026-09-08 00:31
A new upstream version is available: 11.0.2 high
A new upstream version 11.0.2 is available, you should consider packaging it.
Created: 2026-08-28 Last update: 2026-09-07 21:02
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-01-01 Last update: 2026-01-01 07:00
3 low-priority security issues in trixie low

There are 3 open security issues in trixie.

3 issues left for the package maintainer to handle:
  • CVE-2026-46338: (needs triaging) PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files from sibling paths that share the same base_path prefix, such as docs and docs_internal. This is a regression of CVE-2023-32309. This issue is fixed in version 10.21.3.
  • CVE-2026-61632: (needs triaging) PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by <img src="..."> by joining the src onto the configured base_path with os.path.normpath and opening the result directly, without verifying that the resolved path stays inside base_path. As a result, an src containing ../ sequences or an absolute path reads a file outside base_path as long as it has an allowed image extension (.png, .jpg, .jpeg, .gif, .svg), and the file's contents are then base64-encoded into the rendered output, disclosing them. An application that renders untrusted Markdown with pymdownx.b64 enabled can therefore leak the contents of image-extension files readable by the process to whoever controls the Markdown or views the output, a targeted file-read bounded by the extension check. This issue has been fixed in version 11.0.
  • CVE-2026-67422: (needs triaging) pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in exponentially many ways, causing catastrophic backtracking. As a result, a single untrusted Markdown line under 50 bytes rendered with markdown.markdown() in each extension's default configuration drives the rendering thread into unbounded CPU usage that grows exponentially with input length, enabling an unauthenticated remote attacker who can submit Markdown to cause denial of service. The exposure is concrete for web applications that render user-supplied Markdown (comments, wikis, issue bodies, live preview), including any app using pymdownx.extra which bundles the vulnerable betterem default, as well as hosted docs/CI systems that build untrusted Markdown. The issue has been fixed in version 11.0.1.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-18 Last update: 2026-09-04 15:02
news
[rss feed]
  • [2026-07-15] pymdown-extensions 11.0.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-12] Accepted pymdown-extensions 11.0.1-1 (source) into unstable (Alexandre Detiste)
  • [2026-07-04] Accepted pymdown-extensions 10.13-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Adrian Bunk)
  • [2026-01-13] pymdown-extensions 10.19.1-3 MIGRATED to testing (Debian testing watch)
  • [2026-01-02] Accepted pymdown-extensions 10.19.1-3 (source) into unstable (Colin Watson)
  • [2025-12-31] Accepted pymdown-extensions 10.19.1-1 (source) into unstable (Colin Watson)
  • [2025-12-30] Accepted pymdown-extensions 10.13-4 (source) into unstable (Dmitry Shachnev)
  • [2025-08-29] pymdown-extensions 10.13-3 MIGRATED to testing (Debian testing watch)
  • [2025-08-27] Accepted pymdown-extensions 10.13-3 (source) into unstable (Dmitry Shachnev)
  • [2025-08-26] Accepted pymdown-extensions 10.13-2 (source) into unstable (Dmitry Shachnev)
  • [2024-12-26] pymdown-extensions 10.13-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-23] Accepted pymdown-extensions 10.13-1 (source) into unstable (Alexandre Detiste)
  • [2024-10-18] pymdown-extensions 10.11.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-16] Accepted pymdown-extensions 10.11.2-1 (source) into unstable (Alexandre Detiste)
  • [2024-08-08] pymdown-extensions 10.9-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-05] Accepted pymdown-extensions 10.9-1 (source) into unstable (Boyuan Yang)
  • [2024-05-03] pymdown-extensions 10.8.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-30] Accepted pymdown-extensions 10.8.1-1 (source) into unstable (Boyuan Yang)
  • [2024-03-26] pymdown-extensions 9.5-5 MIGRATED to testing (Debian testing watch)
  • [2024-03-23] Accepted pymdown-extensions 9.5-5 (source) into unstable (Dmitry Shachnev)
  • [2024-03-07] pymdown-extensions 9.5-4 MIGRATED to testing (Debian testing watch)
  • [2024-03-01] Accepted pymdown-extensions 9.5-4 (source) into unstable (Sandro Tosi)
  • [2024-03-01] Accepted pymdown-extensions 9.5-3 (source) into unstable (Sandro Tosi)
  • [2022-07-16] pymdown-extensions 9.5-2 MIGRATED to testing (Debian testing watch)
  • [2022-07-01] Accepted pymdown-extensions 9.5-2 (source) into unstable (Sandro Tosi)
  • [2022-07-01] Accepted pymdown-extensions 9.5-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Sandro Tosi)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 11.0.1-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing