Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41680

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.

A flaw was found in marked, a markdown parser and compiler. An unauthenticated attacker can exploit this Denial of Service (DoS) vulnerability by providing a specific 3-byte input sequence (a tab, a vertical tab, and a newline). This input triggers an infinite recursion loop during parsing, leading to unbounded memory allocation and causing the host Node.js application to crash due to Memory Exhaustion (OOM).

Меры по смягчению последствий

To mitigate this vulnerability, Red Hat products that utilize the 'marked' library should be configured to process markdown content only from trusted sources. If markdown rendering is not a critical function, consider disabling or restricting its use within the application's configuration to reduce exposure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Not affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-419-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-ossmc-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel9Not affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/gateway-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-tech-preview/mcp-server-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2461603marked: Marked: Denial of Service via specific input sequence

EPSS

Процентиль: 27%
0.00342
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.

CVSS3: 7.5
nvd
4 месяца назад

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.

CVSS3: 7.5
debian
4 месяца назад

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a cri ...

CVSS3: 7.5
github
3 месяца назад

Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer

EPSS

Процентиль: 27%
0.00342
Низкий

7.5 High

CVSS3