CVE-2021-26813

NameCVE-2021-26813
Descriptionmarkdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs984668

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-markdown2 (PTS)buster2.3.7-2+deb10u1vulnerable
bullseye2.3.10-1.1fixed
bookworm2.4.1-1fixed
sid, trixie2.4.11-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-markdown2source(unstable)2.3.10-1.1984668

Notes

[buster] - python-markdown2 <no-dsa> (Minor issue)
https://github.com/trentm/python-markdown2/pull/387
https://github.com/trentm/python-markdown2/commit/96dff22341489459c8cb832fdfd066a588ec23bf
https://github.com/trentm/python-markdown2/commit/e1954d3a345fc7a4ccc113bd58f7df81ad63b6ec
https://github.com/trentm/python-markdown2/commit/c4b4ccb3f9da33f29b013d6d765fd223a8277cfe

Search for package or bug name: Reporting problems