CVE-2018-25110 Affecting node-marked package, versions <0.5.1+dfsg-1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.05% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN11-NODEMARKED-10245164
  • published25 May 2025
  • disclosed23 May 2025

Introduced: 23 May 2025

NewCVE-2018-25110  (opens in a new tab)

How to fix?

Upgrade Debian:11 node-marked to version 0.5.1+dfsg-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream node-marked package and not the node-marked package as distributed by Debian. See How to fix? for Debian:11 relevant fixed versions and status.

Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.