CVE-2021-26813

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/03/2021
Last modified:
07/11/2023

Description

markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:markdown2_project:markdown2:*:*:*:*:*:*:*:* 1.0.1.18 (including) 2.4.0 (excluding)
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*