DirectorySecurity Advisories
Sign In
Security Advisories

CGA-f36g-f6vf-h9wv

Published

Last updated

https://images.chainguard.dev/security/CGA-f36g-f6vf-h9wv
Package

gitlab-rails-ee-fips-17.5

Latest Update
Pending upstream fix
Aliases
  • GHSA-wx77-rp39-c6vg

Summary

Regular Expression Denial of Service in markdown

Description

All versions of markdown are vulnerable to Regular Expression Denial of Service (ReDoS). The markdown.toHTML() function has significantly degraded performance when parsing long strings containing underscores. This may lead to Denial of Service if the parser accepts user input.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

References

  • https://github.com/advisories/GHSA-wx77-rp39-c6vg

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images