Vulnerabilities/

Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing

Severity:
Medium

Description

Showdownjs, versions <= 2.1.0, anchors subparser used to parse links has a nested regular expression which can lead to denial of service conditions given malicious input.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
showdown
Anything's wrong? Let us know Last updated on April 24, 2026