/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-mq82-gfgr-37rr

Published

Last updated

https://images.chainguard.dev/security/CGA-mq82-gfgr-37rr
Package

gitlab-rails-ee-fips-17.9

Repository

Chainguard

Latest Update
Not affected
Aliases
  • GHSA-wx77-rp39-c6vg

Summary

Regular Expression Denial of Service in markdown

Description

All versions of markdown are vulnerable to Regular Expression Denial of Service (ReDoS). The markdown.toHTML() function has significantly degraded performance when parsing long strings containing underscores. This may lead to Denial of Service if the parser accepts user input.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

References

  • https://github.com/advisories/GHSA-wx77-rp39-c6vg

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs