VYPR
Moderate severityNVD Advisory· Published Feb 12, 2026· Updated Feb 12, 2026

CVE-2026-2327

CVE-2026-2327

Description

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
markdown-itnpm
>= 13.0.0, < 14.1.114.1.1

Affected products

23

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.