Bug 2175704 (CVE-2023-26303) - CVE-2023-26303 markdown-it-py: Denial of service by forcing null assertions with specially crafted input
Summary: CVE-2023-26303 markdown-it-py: Denial of service by forcing null assertions w...
Keywords:
Status: NEW
Alias: CVE-2023-26303
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2175705 2175706
Blocks: 2172788
TreeView+ depends on / blocked
 
Reported: 2023-03-06 11:33 UTC by Vipul Nair
Modified: 2025-04-01 08:28 UTC (History)
18 users (show)

Fixed In Version: markdown-it-py 2.2.0
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Vipul Nair 2023-03-06 11:33:54 UTC
CVE-2023-26303
Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input.

https://github.com/executablebooks/markdown-it-py/commit/ae03c6107dfa18e648f6fdd1280f5b89092d5d49

Comment 1 Vipul Nair 2023-03-06 11:36:05 UTC
Created ansible-lint tracking bugs for this issue:

Affects: fedora-all [bug 2175705]


Created python-ansible-compat tracking bugs for this issue:

Affects: fedora-all [bug 2175706]


Note You need to log in before you can comment on or make changes to this bug.