Inefficient Algorithmic Complexity in Comrak - #VU147262
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the autolink_delim function when processing untrusted Markdown containing URLs with many trailing closing parentheses. A remote attacker can submit specially crafted Markdown to cause a denial of service.
The issue is reachable only when the GFM autolink extension is enabled.