CVE-2018-25110
published 2025-05-23CVE-2018-25110: Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.51%
40.9th percentile
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-marked | < node-marked 0.5.1+dfsg-1 (bookworm) | node-marked 0.5.1+dfsg-1 (bookworm) |
| marked_project | marked | < 0.3.17 | 0.3.17 |
| marked_project | marked | >= 0 < 0.3.17 | 0.3.17 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.9MEDIUM
vendor_debian6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-25110: node-marked - Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of S...
vendor_debian·2018·CVSS 6.9
CVE-2018-25110 [MEDIUM] CVE-2018-25110: node-marked - Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of S...
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
Scope: local
bookworm: resolved (fixed in 0.5.1+dfsg-1)
bullseye: resolved (fixed in 0.5.1+dfsg-1)
forky: resolved (fixed in 0.5.1+dfsg-1)
sid: resolved (fixed in 0.5.1+dfsg-1)
trixie: resolved (fixed in 0.5.1+dfsg-1)
OSV
Marked allows Regular Expression Denial of Service (ReDoS) attacks
osv·2025-05-23
CVE-2018-25110 [MEDIUM] Marked allows Regular Expression Denial of Service (ReDoS) attacks
Marked allows Regular Expression Denial of Service (ReDoS) attacks
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
OSV
CVE-2018-25110: Marked prior to version 0
osv·2025-05-23·CVSS 6.9
CVE-2018-25110 [MEDIUM] CVE-2018-25110: Marked prior to version 0
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
GHSA
Marked allows Regular Expression Denial of Service (ReDoS) attacks
ghsa·2025-05-23
CVE-2018-25110 [MEDIUM] CWE-1333 Marked allows Regular Expression Denial of Service (ReDoS) attacks
Marked allows Regular Expression Denial of Service (ReDoS) attacks
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
No detection rules found.
No public exploits indexed.
2025-05-23
Published