VDB
Sign up
LOW

GHSA-wx77-rp39-c6vg

Regular Expression Denial of Service in markdown

Details

All versions of `markdown` are vulnerable to Regular Expression Denial of Service (ReDoS). The `markdown.toHTML()` function has significantly degraded performance when parsing long strings containing underscores. This may lead to Denial of Service if the parser accepts user input.

## Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/markdown
Introduced in: 0.0.0

No fixed version published yet for markdown (npm). Pin to a known-safe version or switch to an alternative.

References