Bug 2461603 (CVE-2026-41680) - CVE-2026-41680 marked: Marked: Denial of Service via specific input sequence
Summary: CVE-2026-41680 marked: Marked: Denial of Service via specific input sequence
Keywords:
Status: NEW
Alias: CVE-2026-41680
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2461791 2461792 2461793 2461794 2461795 2461797 2461798 2461799 2461800 2461801 2461796 2461802 2461804
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-24 18:01 UTC by OSIDB Bzimport
Modified: 2026-05-05 08:47 UTC (History)
102 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-24 18:01:42 UTC
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)β€”an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.


Note You need to log in before you can comment on or make changes to this bug.