Vendorsmarkdown-it Projectmarkdown-itany version
Vulnerabilities

markdown-it Project markdown-it any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2015-10005
markdown-it html_re.js redos
Published 2022-12-27 · Modified
7.5EPSS 0.009
CVE-2026-2327
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition.
Published 2026-02-12 · Analyzed
7.5EPSS 0.007
CVE-2022-21670
Uncontrolled Resource Consumption in markdown-it
Published 2022-01-10 · Modified
5.3EPSS 0.022
CVE-2026-48988
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
Published 2026-06-17 · Analyzed
5.3EPSS 0.004