Description
A critical Denial of Service (DoS) vulnerability exists in [email protected]. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.
Recommendation
Update the marked package to the latest compatible version. Followings are version details:
- Affected version(s): >= 18.0.0, <= 18.0.1
- Patched version(s): 18.0.2
References
Could your website be exposed too?
SmartScanner can check your website for Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
- jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder - CVE-2026-24133
- protobufjs: Denial of Service via infinite loop in .proto option parsing - CVE-2026-59877
- ExifReader is vulnerable to denial of service via unbounded decompression of image metadata - CVE-2026-8814


