comrak is vulnerable to Denial of Service (DoS)
22
Low Risk
Affected versions of this package are vulnerable to denial-of-service (DoS) attacks due to a stack overflow during footnote resolution. Deeply nested elements could trigger excessive recursion, leading to application crashes. To mitigate this, footnote resolution has been refactored to avoid recursion, and inline footnotes are now limited to a nesting depth of five.
You are affected if you are using a version that falls within the vulnerable range.
comrak is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.45.0.
Upgrade the comrak library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant