Inefficient Algorithmic Complexity in markdown-it - #VU146761
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in linkify handling when parsing crafted markdown input with linkify: true. A remote attacker can send specially crafted markdown content to cause a denial of service.
Only applications that enable the linkify option are vulnerable. The issue is availability-only and can block the event loop for tens of seconds with a few hundred kilobytes of ordinary-looking markdown.