PT-2021-17146 · Markdown2+1 · Markdown2+1

Ben Caller

·

Published

2021-03-03

·

Updated

2024-07-12

·

CVE-2021-26813

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: markdown2 versions 1.0.1.18 through 2.3.x
Description: The issue allows an attacker to cause a denial of service by providing a malicious string, making markdown2 processing difficult or delayed for an extended period. This occurs due to a regular expression denial of service vulnerability.
Recommendations: For markdown2 versions 1.0.1.18 through 2.3.x, update to version 2.4.0 to resolve the issue.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2021-26813
GHSA-JR9P-R423-9M2R
OPENSUSE-SU-2021:0429-1
OPENSUSE-SU-2021:0451-1
OPENSUSE-SU-2021_0429-1
OPENSUSE-SU-2024:11237-1
OPENSUSE-SU-2024:14146-1
PYSEC-2021-20

Affected Products

Suse
Markdown2