Junglewise Threat Intelligence

CVE-2021-21254: CKEditor 5 Markdown plugin regular expression denial of service

CVE-2021-21254 · Severity: low · CVSS 3.1 · Published 2021-01-29

Vendors: npm.

Executive brief

CKEditor 5 is a popular rich-text editor used in web applications to allow users to create and edit content. The Markdown plugin contains a flaw in its link recognition logic that can be exploited by sending specially crafted input, causing the editor to consume excessive CPU and freeze the browser tab, disrupting user productivity.

Technical details

A regular expression denial of service (ReDoS) vulnerability exists in the CKEditor 5 Markdown plugin's link recognition regex pattern (CWE-400). An attacker can craft input containing specific character sequences that trigger catastrophic backtracking in the regex engine, causing significant performance degradation and browser tab freeze. The vulnerability affects versions up to 24.0.0 and requires network access to a web application using the vulnerable plugin, with no authentication or user interaction required beyond viewing or entering text. The fix is available in version 25.0.0 or users can mitigate by disabling the Markdown plugin entirely.

Affected products

  • CKSource CKEditor 5 Markdown plugin <= 24.0.0

Timeline

  • 2021-01-29: disclosed
  • 2021: patched: Fix available in version 25.0.0

References

Related threats