Duplicate Advisory: Regular Expression Denial of Service in simple-markdown
Moderate severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Feb 3, 2026
Withdrawn
This advisory was withdrawn on Feb 3, 2026
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Withdrawn
Feb 3, 2026
Last updated
Feb 3, 2026
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-gpvj-gp8c-c7p2. This link is maintained to preserve external references.
Original Description
Versions of
simple-markdownprior to 0.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS). TheSimpleMarkdown.defaultInlineParse()function has significantly degraded performance when parsing inline code blocks.Recommendation
Upgrade to version 0.5.2 or later.
References