By vendor
Markdown-It_project vulnerabilities
Known CVEs affecting Markdown-It_project products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-48988MEDIUM 5.3
markdown-it, a widely-used Markdown parser, contains a denial-of-service vulnerability in versions 14.1.1 and earlier when the typographer feature is enabled. When processing Markdown text with many quotation marks, the parser consumes excessive CPU due to inefficient string manipulation, potentially allowing an attacker to degrade service availability by submitting specially-crafted Markdown. The vulnerability is fixed in version 14.2.0. Although the typographer feature is off by default, many production applications enable it for enhanced typography, making this issue relevant to deployed systems.