VDB
Sign up
MEDIUM5.3

GHSA-xf5p-87ch-gxw2

Marked ReDoS due to email addresses being evaluated in quadratic time

Quick fix

GHSA-xf5p-87ch-gxw2 — marked: upgrade to the fixed version with the command below.

npm install marked@0.6.2

Details

Versions of `marked` from 0.3.14 until 0.6.2 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic time, allowing attackers to potentially crash the node process due to resource exhaustion.

## Recommendation

Upgrade to version 0.6.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/marked
Introduced in: 0.3.14Fixed in: 0.6.2
Fixnpm install marked@0.6.2

References