Vulnerabilities/

markdown-it is has a Regular Expression Denial of Service (ReDoS)

Severity:
Medium

Description

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /*+$/ in the linkify function.

Recommendation

Update the markdown-it package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
markdown-it
Anything's wrong? Let us know Last updated on February 13, 2026