Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function
Remediation
References
https://research.jfrog.com/vulnerabilities/markdown-link-extractor-redos-xray-211350/
Related Vulnerabilities
CVE-2021-23358 Vulnerability in npm package underscore
CVE-2020-8158 Vulnerability in npm package typeorm
CVE-2018-18853 Vulnerability in maven package io.spray:spray-json_2.11
CVE-2018-20835 Vulnerability in npm package tar-fs
CVE-2023-34453 Vulnerability in maven package org.xerial.snappy:snappy-java