Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-43308: markdown-link-extractor ReDoS | XRAY-211350

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module’s exported function

CVE
#dos#nodejs

CVE-2021-43308 | CVSS 5.9

JFrog Severity:medium

Published 30 May. 2022 | Last updated 30 May. 2022

Exponential ReDoS in markdown-link-extractor leads to denial of service

markdown-link-extractor

markdown-link-extractor (,3.0.1]|[4.0.0], fixed in 3.0.2 and 4.0.1

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module’s exported function

'![' + '"\\"’.repeat(i))

No mitigations are supplied for this issue

NVD

Related news

GHSA-mmh6-m7v9-5956: Regular expression denial of service in markdown-link-extractor

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907