Executive brief
marked is a popular JavaScript library for parsing and rendering Markdown content. A regular expression flaw in the library can cause severe performance degradation when processing malformed Markdown input, potentially slowing or blocking legitimate document processing.
Technical details
This vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in marked's _label subrule. The affected regex pattern exhibits catastrophic backtracking when processing specially crafted or malformed Markdown input, causing exponential performance degradation. The vulnerability affects marked versions 0.4.0 through 0.6.x; it requires only network-reachable input (no authentication) and can be triggered by sending a single malicious Markdown string. An attacker can exhaust CPU resources and degrade or block parsing of legitimate documents. The fix is available in version 0.7.0 and later.
Affected products
- marked marked 0.4.0 to 0.6.x
Timeline
- 2020-09-03: disclosed