python-markdown2 through 2.3.8 allows XSS because element names are mishandled unless a \w+ match succeeds. For example, an attack might use elementname@ or elementname- with an onclick attribute.
https://github.com/trentm/python-markdown2/issues/348
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00035.html
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00031.html