Resource exhaustion in markdown-it - CVE-2026-48988
Published: May 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the smartquotes rule when processing user-supplied markdown with the typographer option enabled. A remote attacker can submit a markdown input containing many consecutive quotation marks to cause a denial of service.
Only applications that render user-supplied markdown with typographer: true are vulnerable.
Affected software
Fedora
nextcloud
How to mitigate CVE-2026-48988
nextcloud - addressed in versions 34.0.4-1.el10_2, 34.0.4-1.el10_4, 34.0.4-1.fc43, 34.0.4-1.fc44, 34.0.4-1.fc45