markdown2 is vulnerable to Regular Expression Denial of Service (ReDoS)
23
Low Risk
Affected versions of this package use a regular expression with inefficient complexity in the HTML tokenizer, specifically within the _run_span_gamut function. This inefficiency can be exploited with specially crafted input to trigger excessive CPU usage, resulting in degraded performance or potential denial-of-service (DoS) conditions due to high computational overhead during parsing.
You are affected if you are using a version that falls within the vulnerable range.
markdown2 is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 1.0.0 - 2.5.3.
Upgrade the markdown2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant