Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-41680

Опубликовано: 24 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.

РелизСтатусПримечание
devel

not-affected

only affects 18.0.0 and 18.0.1
esm-apps-legacy/xenial

not-affected

only affects 18.0.0 and 18.0.1
esm-apps/bionic

not-affected

only affects 18.0.0 and 18.0.1
esm-apps/focal

not-affected

only affects 18.0.0 and 18.0.1
esm-apps/jammy

not-affected

only affects 18.0.0 and 18.0.1
esm-apps/noble

not-affected

only affects 18.0.0 and 18.0.1
esm-apps/resolute

not-affected

only affects 18.0.0 and 18.0.1
esm-apps/xenial

not-affected

only affects 18.0.0 and 18.0.1
jammy

not-affected

only affects 18.0.0 and 18.0.1
noble

not-affected

only affects 18.0.0 and 18.0.1

Показывать по

EPSS

Процентиль: 27%
0.00342
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
4 месяца назад

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.

CVSS3: 7.5
nvd
4 месяца назад

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.

CVSS3: 7.5
debian
4 месяца назад

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a cri ...

CVSS3: 7.5
github
3 месяца назад

Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer

EPSS

Процентиль: 27%
0.00342
Низкий

7.5 High

CVSS3