Resource exhaustion in markdown-it - CVE-2026-48988
Published: May 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the smartquotes rule when processing user-supplied markdown with the typographer option enabled. A remote attacker can submit a markdown input containing many consecutive quotation marks to cause a denial of service.
Only applications that render user-supplied markdown with typographer: true are vulnerable.