Uncontrolled Resource Consumption in markdown-it
Moderate severity
GitHub Reviewed
Published
Jan 8, 2022
in
markdown-it/markdown-it
•
Updated Jul 24, 2023
Description
Published by the National Vulnerability Database
Jan 10, 2022
Reviewed
Jan 10, 2022
Published to the GitHub Advisory Database
Jan 12, 2022
Last updated
Jul 24, 2023
Impact
Special patterns with length > 50K chars can slow down parser significantly.
Patches
Upgrade to v12.3.2+
Workarounds
No.
References
Fix + test sample: markdown-it/markdown-it@ffc49ab
References