Regular Expression Denial of Service
Moderate severity
GitHub Reviewed
Published
Feb 25, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Withdrawn
This advisory was withdrawn on Feb 25, 2021
Description
Reviewed
Jun 4, 2019
Published to the GitHub Advisory Database
Feb 25, 2021
Withdrawn
Feb 25, 2021
Last updated
Jan 9, 2023
A flaw was found in nodejs-marked versions from 0.5.0 to before 0.6.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). Input to the host variable is vulnerable when input contains parenthesis in link URIs, coupled with a high number of link tokens in a single line.
References