Junglewise Threat Intelligence

marked regular expression denial of service

Severity: info · Published 2020-09-03

Technologies: Marked.

Executive brief

marked is a popular JavaScript library for parsing and rendering Markdown content. A regular expression flaw in the library can cause severe performance degradation when processing malformed Markdown input, potentially slowing or blocking legitimate document processing.

Technical details

This vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in marked's _label subrule. The affected regex pattern exhibits catastrophic backtracking when processing specially crafted or malformed Markdown input, causing exponential performance degradation. The vulnerability affects marked versions 0.4.0 through 0.6.x; it requires only network-reachable input (no authentication) and can be triggered by sending a single malicious Markdown string. An attacker can exhaust CPU resources and degrade or block parsing of legitimate documents. The fix is available in version 0.7.0 and later.

Affected products

  • marked marked 0.4.0 to 0.6.x

Timeline

  • 2020-09-03: disclosed

References