CVE-2022-21670

Uncontrolled Resource Consumption in markdown-it in npm/markdown-it

Identifiers

CVE-2022-21670, GHSA-6vfc-qv3f-vr6c

Package Slug

npm/markdown-it

Vulnerability

Uncontrolled Resource Consumption in markdown-it

Description

markdown-it is a Markdown parser. special patterns with length greater than thousand characterss could slow down the parser significantly. Users should upgrade to to receive a patch. There are no known workarounds aside from upgrading.

Affected Versions

All versions up to 12.3.1

Solution

Upgrade to version 12.3.2 or above.

Last Modified

2022-01-13

source