Description
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function
Remediation
References
https://research.jfrog.com/vulnerabilities/markdown-link-extractor-redos-xray-211350/
Related Vulnerabilities
CVE-2020-14968 Vulnerability in npm package jsrsasign
CVE-2023-0835 Vulnerability in npm package markdown-pdf
CVE-2020-8205 Vulnerability in npm package @uppy/companion
CVE-2023-29518 Vulnerability in maven package org.xwiki.platform:xwiki-platform-invitation-ui
CVE-2021-44585 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base