Junglewise Threat Intelligence

CVE-2019-25103: simple-markdown regular expression denial of service

CVE-2019-25103 · Severity: low · CVSS 3.1 · Published 2023-02-12

Technologies: simple-markdown (npm). Vendors: npm.

Executive brief

simple-markdown is a JavaScript library used to convert markdown text into HTML. A regular expression parsing flaw allows an attacker to craft malicious input that causes the parser to consume excessive CPU resources, resulting in application slowdown or unavailability. This could impact any web application or service that uses simple-markdown to process untrusted user input.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw affecting the markdown parsing logic in simple-markdown.js, classified as CWE-1333 (inefficient regular expression complexity). An attacker can provide specially crafted markdown input to the parser that triggers catastrophic backtracking in one or more regular expressions, causing the parser to hang or consume significant CPU cycles. The attack requires no authentication and can be launched remotely against any service that accepts markdown input. The vulnerability affects all versions prior to 0.5.2, which includes a patch (commit 89797fef9abb4cab2fb76a335968266a92588816) that optimizes the affected regular expressions. Upgrading to version 0.5.2 or later resolves the issue.

Affected products

  • Khan Academy simple-markdown before 0.5.2

Timeline

  • 2023-02-12: disclosed
  • 0.5.2: patched: Upgrade to version 0.5.2 or later

References

Related threats