Resource exhaustion in markdown-it - #VU132289
Published: May 25, 2026
markdown-it
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the smartquotes rule when processing user-supplied markdown with the typographer option enabled. A remote attacker can submit a markdown input containing many consecutive quotation marks to cause a denial of service.
Only applications that render user-supplied markdown with typographer: true are vulnerable.