Vulnerabilities/

Regular Expression Denial of Service in markdown

Severity:
Low

Description

All versions of markdown are vulnerable to Regular Expression Denial of Service (ReDoS). The markdown.toHTML() function has significantly degraded performance when parsing long strings containing underscores. This may lead to Denial of Service if the parser accepts user input.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
markdown
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing