cbcvebase.
CVE-2026-41680
published 2026-04-24

CVE-2026-41680: Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.34%
26.4th percentile
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.

Affected

21 ranges
VendorProductVersion rangeFixed in
ansible-automation-platformautomation-portal
apicurioapicurio-registry-ui-rhel8
apicurioapicurio-registry-ui-rhel9
apicurioapicurio-studio-ui-rhel8
grafanagrafana
marked_projectmarked
marked_projectmarked>= 18.0.0 < 18.0.218.0.2
marked_projectmarked>= 18.0.0 < 18.0.218.0.2
markedjsmarked
migration-toolkit-virtualizationmtv-console-plugin-rhel9
openshift-gitops-1argocd-rhel8
openshift-gitops-1argocd-rhel9
openshift4ose-console-rhel9
openshift4ose-monitoring-plugin-rhel9
rhcephalloy-rhel10
rhdesktoprh-podman-desktop-ext-bootc-rhel10
rhoaiodh-dashboard-rhel9
rhoaiodh-mod-arch-maas-rhel9
rhoaiodh-mod-arch-model-registry-rhel9
satelliteiop-advisor-frontend-rhel9
satelliteiop-vulnerability-frontend-rhel9

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.