Description
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers excessive backtracking and may lead to a denial-of-service condition.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ajax Multi Upload 'upload.php' Arbitrary File Upload (1.1)
WordPress Plugin Under Construction Unspecified Vulnerability (3.25)
Internet Information Services Other Vulnerability (CVE-2000-0951)
WordPress Plugin Video Gallery-Vimeo and YouTube Gallery Cross-Site Scripting (1.1.4)
WordPress Plugin TAKETIN To WP Membership PHP Object Injection (1.2.7)