Junglewise Threat Intelligence

CVE-2021-26813: PYSEC-2021-20 - markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicio

CVE-2021-26813 · Severity: low · CVSS 3.1 · Published 2021-03-03

Technologies: markdown2 (PyPI). Vendors: PyPI.

Executive brief

markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.

Affected products

  • PyPI markdown2

Related threats