Bug 2374238 (CVE-2025-6493)

Summary: CVE-2025-6493 codemirror: CodeMirror Markdown Regex Complexity Vulnerability
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abarbaro, asoldano, bbaranow, bmaxwell, brian.stansberry, cdaley, cdewolf, darran.lofthouse, dhanak, dkreling, dosoudil, drosa, dsimansk, erack, fjuma, gmalinko, gotiwari, istudens, ivassile, iweiss, janstey, jchui, jhe, jhorak, kingland, ktsao, kverlaen, lgao, matzew, mnovotny, mosmerov, msochure, msvehla, mvyas, nboldt, nwallace, pdelbell, pesilva, pjindal, pmackay, psrna, rstancel, rstepani, sausingh, sdawley, smaestri, tom.jenkinson, tpopela
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in codemirror. The markdown.js file within the Markdown Mode component exhibits inefficient regular expression usage, leading to excessive resource consumption. This flaw allows a remote attacker to provide a specially crafted file. This inefficient processing can result in a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2025-06-22 23:01:06 UTC
A vulnerability was found in CodeMirror up to 5.17.0 and classified as problematic. Affected by this issue is some unknown functionality of the file mode/markdown/markdown.js of the component Markdown Mode. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Not all code samples mentioned in the GitHub issue can be found. The repository mentions, that "CodeMirror 6 exists, and is [...] much more actively maintained."