The Markdown2 Project maintains a focused Markdown-to-HTML conversion library whose vulnerability footprint centers on a single product, markdown2, and the text-parsing attack surface inherent to such converters. The durable signal in the vendor's disclosures is recurrent inefficient regular-expression complexity, a weakness class that reflects the parsing demands of a format-conversion utility. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Markdown2 Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26813HIGH markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 process | Mar 3, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Markdown2 Project.
Media articles that mention a CVE ID that affects a product developed by Markdown2 Project — matched by CVE ID, not by vendor name.