PT-2025-22799 · Marked · Marked
Published
2025-05-23
·
Updated
2025-05-26
·
CVE-2018-25110
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Marked versions prior to 0.3.17
Description
The issue is related to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
Recommendations
For versions prior to 0.3.17, update to version 0.3.17 or later to resolve the issue. As a temporary workaround, consider restricting the use of markdown input to prevent exploitation until a patch is applied. Avoid using deeply nested or repetitively structured brackets or tag attributes in markdown links to minimize the risk of exploitation.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marked