#VU86811 Inefficient regular expression complexity in Showdown - CVE-2024-1899
Published: February 27, 2024
Showdown
Showdownjs
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation in subparser when processing links with a regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.