Executive brief
marked is a popular open-source Markdown parser used in many JavaScript applications to convert Markdown text into HTML. A regular expression flaw in the parser can be exploited by providing specially crafted input to cause a denial of service, where the application becomes unresponsive for several seconds even with relatively small payloads. This can disrupt availability of services that rely on marked to process user-supplied or external content.
Technical details
The vulnerability is a regular expression denial of service (ReDoS) vulnerability caused by inefficient pattern matching in marked's parser logic (CWE-400). The affected regular expression exhibits catastrophic backtracking when processing adversarial input, with documented amplification such that approximately 1,000 characters of malicious Markdown can block the Node.js event loop for around 6 seconds. The attack requires only network-level access to send malicious Markdown input—no authentication or user interaction beyond normal usage is required. An attacker can exploit this to cause denial of service against any application using vulnerable versions of marked. The vulnerability was fixed in version 0.3.9 and later.
Affected products
- marked marked before 0.3.9
Timeline
- 2018-07-24: disclosed
- 2017: patched: Fix released in version 0.3.9