CVE-2021-26813

NameCVE-2021-26813
Descriptionmarkdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs984668

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-markdown2 (PTS)buster2.3.7-2+deb10u1vulnerable
bullseye, sid2.3.10-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-markdown2source(unstable)(unfixed)984668

Notes

[buster] - python-markdown2 <no-dsa> (Minor issue)
https://github.com/trentm/python-markdown2/pull/387

Search for package or bug name: Reporting problems