ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-48801
linkify-it is a links recognition library with full Unicode support.

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.

NVD description · AI analysis pending
8.7<1% PoC
  • markdown-it linkify-it
CVE-2026-59887
linkify-it is a links recognition library with full Unicode support.

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.

NVD description · AI analysis pending
7.5<1% PoC
  • markdown-it linkify-it
CVE-2026-48988
markdown-it is a Markdown parser.

markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per quote character. This can cause excessive CPU consumption when parsing quote-heavy, user-supplied markdown and may let attackers degrade or disrupt service availability. Although typographer is disabled by default, many production apps enable it for smart typography, making the issue relevant. This issue has been fixed in version 14.2.0.

NVD description · AI analysis pending
5.3<1% PoC
  • markdown-it project markdown-it
CVE-2026-2327
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition.

NVD description · AI analysis pending
5.5<1%
  • markdown-it project markdown-it
CVE-2025-7969
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS).

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs. This issue affects markdown-it: 14.1.0. NOTE: the Supplier does not consider this issue to be a vulnerability.

NVD description · AI analysis pending
6.9<1% PoC
  • markdown-it project markdown-it
CVE-2020-28459
This affects all versions of package markdown-it-decorate.

This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.

NVD description · AI analysis pending
6.1<1% PoC
  • markdown-it-decorate project markdown-it-decorate
CVE-2020-28455
This affects all versions of package markdown-it-toc.

This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

NVD description · AI analysis pending
6.1<1% PoC
  • markdown-it-toc project markdown-it-toc
CVE-2022-21670
markdown-it is a Markdown parser.

markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading.

NVD description · AI analysis pending
5.32% PoC
  • markdown-it project markdown-it
CVE-2020-7773
This affects the package markdown-it-highlightjs before 3.3.1.

This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const markdownItHighlightjs = require("markdown-it-highlightjs"); const md = require('markdown-it'); const reuslt_xss = md() .use(markdownItHighlightjs, { inline: true }) .render('console.log(42){.">js}'); console.log(reuslt_xss);

NVD description · AI analysis pending
6.11% PoC
  • markdown-it-highlightjs project markdown-it-highlightjs