Medium severity5.3NVD Advisory· Published Jan 10, 2022· Updated Jun 17, 2026
CVE-2022-21670
CVE-2022-21670
Description
markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
markdown-itnpm | < 12.3.2 | 12.3.2 |
Affected products
2- markdown-it/markdown-itv5Range: < 12.3.2
Patches
Vulnerability mechanics
References
4- github.com/markdown-it/markdown-it/commit/ffc49ab46b5b751cd2be0aabb146f2ef84986101nvdPatchThird Party AdvisoryWEB
- github.com/markdown-it/markdown-it/security/advisories/GHSA-6vfc-qv3f-vr6cnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-6vfc-qv3f-vr6cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-21670ghsaADVISORY
News mentions
0No linked articles in our index yet.