High severity7.5NVD Advisory· Published Jan 14, 2022· Updated Jun 17, 2026
CVE-2022-21680
CVE-2022-21680
Description
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression block.def may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
markednpm | < 4.0.10 | 4.0.10 |
Affected products
5cpe:2.3:a:marked_project:marked:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:marked_project:marked:*:*:*:*:*:node.js:*:*range: <4.0.10
- (no CPE)range: < 4.0.10
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- osv-coords2 versions
< 3.12.9.4-r14+ 1 more
- (no CPE)range: < 3.12.9.4-r14
- (no CPE)range: < 4.0.10
Patches
Vulnerability mechanics
References
7- github.com/markedjs/marked/commit/c4a3ccd344b6929afa8a1d50ac54a721e57012c0nvdPatchThird Party AdvisoryWEB
- github.com/markedjs/marked/security/advisories/GHSA-rrrm-qjm4-v8hfnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-rrrm-qjm4-v8hfghsaADVISORY
- github.com/markedjs/marked/releases/tag/v4.0.10nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-21680ghsaADVISORY
- lists.fedoraproject.org/archives/list/[email protected]/message/AIXDMC3CSHYW3YWVSQOXAWLUYQHAO5UXghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AIXDMC3CSHYW3YWVSQOXAWLUYQHAO5UX/nvd
News mentions
0No linked articles in our index yet.