VDB
Sign up
—

PYSEC-2021-20

Quick fix

PYSEC-2021-20 — markdown2: upgrade to the fixed version with the command below.

pip install --upgrade 'markdown2>=2.4.0'

Details

markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/markdown2
Introduced in: 1.0.1.18Fixed in: 2.4.0
Fixpip install --upgrade 'markdown2>=2.4.0'

References