Description
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /*+$/ in the linkify function.
Recommendation
Update the markdown-it package to the latest compatible version. Followings are version details:
- Affected version(s): >= 13.0.0, < 14.1.1
- Patched version(s): 14.1.1
References
Could your website be exposed too?
SmartScanner can check your website for markdown-it is has a Regular Expression Denial of Service (ReDoS) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability - CVE-2026-22809
- Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection - CVE-2026-44496
- semver-regex Regular Expression Denial of Service (ReDOS) - CVE-2021-3795
- Regular Expression Denial of Service (ReDoS) in ua-parser-js - CVE-2021-27292


