CVE-2026-2327 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*…
Medium CVSS: 5.5

CVE-2026-2327

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition.
Vendor
Markdown-it Project
Product
Markdown-it
CWE
CWE-1333
Yayın Tarihi
2026-02-12 06:16:02
Güncelleme
2026-02-23 14:08:11
Source Identifier
report@snyk.io
KEV Date Added
-

Kategoriler

Referanslar