LOW
GHSA-wx77-rp39-c6vg
Regular Expression Denial of Service in markdown
Details
All versions of `markdown` are vulnerable to Regular Expression Denial of Service (ReDoS). The `markdown.toHTML()` function has significantly degraded performance when parsing long strings containing underscores. This may lead to Denial of Service if the parser accepts user input.
## Recommendation
No fix is currently available. Consider using an alternative package until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/markdown
Introduced in:
0.0.0No fixed version published yet for markdown (npm). Pin to a known-safe version or switch to an alternative.