Regular Expression Denial of Service in marked
Low severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Apr 11, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Last updated
Apr 11, 2023
Affected versions of
marked
are vulnerable to Regular Expression Denial of Service (ReDoS). The_label
subrule may significantly degrade parsing performance of malformed input.Recommendation
Upgrade to version 0.7.0 or later.
References