Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29566
HistoryMar 04, 2021 - 4:44 a.m.

Regular Expression Denial Of Service (ReDoS)

2021-03-0404:44:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
regular expression denial of service
vulnerability
parsing
resource consumption
whitespace
newline
string
software

EPSS

0.003

Percentile

69.8%

markdown2 is vulnerable to regular expression denial of service (ReDoS). The vulnerability exists as the regular expressions found in self.regex_defns, _fenced_code_block_re, and _emacs_oneliner_vars_pat causes a huge consumption of resources when parsing strings with many whitespace or newline characters.