PT-2026-35040 · Marked.Js · Marked

Published

2026-04-24

·

Updated

2026-04-24

·

CVE-2026-41680

CVSS v4.0

8.7

High

AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (x09x0b )—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.

Exploit

Fix

DoS

Uncontrolled Recursion

Infinite Loop

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-41680

Affected Products

Marked