CVE-2026-2327Disclosure(markdown-it_project / markdown-it)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • markdown-it

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
markdown-it

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-12: 2Technical Details · 2026-02-12: 202-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2327 Regular Expression Denial of Service (ReDoS) in markdown-it Package Before 14.1.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2327

    Post summary

    The text announces CVE-2026-2327, a ReDoS vulnerability in markdown-it prior to version 14.1.1, without any evidence of exploitation, PoC, or patching.

    0001066
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2327 Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in t… https://www.cve.org/CVERecord?id=CVE-2026-2327

    Post summary

    The message discloses a ReDoS flaw in markdown-it versions 13.0.0 through 14.1.1 caused by a specific regex pattern.

    00000380
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmarkdown-it_projectmarkdown-it---

Explore more