MEDIUM5.3
GHSA-xf5p-87ch-gxw2
Marked ReDoS due to email addresses being evaluated in quadratic time
Quick fix
GHSA-xf5p-87ch-gxw2 — marked: upgrade to the fixed version with the command below.
npm install marked@0.6.2Details
Versions of `marked` from 0.3.14 until 0.6.2 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic time, allowing attackers to potentially crash the node process due to resource exhaustion.
## Recommendation
Upgrade to version 0.6.2 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/markedjs/marked/pull/1460[WEB]
- https://github.com/markedjs/marked/commit/b15e42b67cec9ded8505e9d68bb8741ad7a9590d[WEB]
- https://github.com/markedjs/marked[PACKAGE]
- https://github.com/markedjs/marked/releases/tag/v0.6.2[WEB]
- https://snyk.io/vuln/SNYK-JS-MARKED-174116[WEB]
- https://www.npmjs.com/advisories/812[WEB]