CVE-2026-2327

EUVD-2026-7037
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 48.48%
Affected Products (NVD)
VendorProductVersion
markdown-it_projectmarkdown-it
13.0.0 ≤
𝑥
< 14.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-markdown-it
bookworm
22.2.3+dfsg+~12.2.3-2
fixed
bullseye
10.0.0+dfsg-2+deb11u1
fixed
forky
22.2.3+dfsg+~12.2.3-5
fixed
sid
22.2.3+dfsg+~12.2.3-5
fixed
trixie
22.2.3+dfsg+~12.2.3-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-markdown-it
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage