Regular Expression Denial of Service (ReDoS) in markedjs/marked
Published May 23, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.58%
Description
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsing HTML tags and markdown links. An attacker can exploit this vulnerability by providing specially crafted markdown input, such as deeply nested or repetitively structured brackets or tag attributes, which cause the parser to hang and lead to a Denial of Service.
Affected products
No data.
- < 0.3.17
No data.
No Red Hat product state for this CVE.
marked
npm
Introduced 0 Fixed 0.3.17
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | marked | 0 | 0.3.17 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed May 23, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.58% (0.00585) | 45.96th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.49% (0.00493) | 38.21th | v5 (v2026.06.15) |
| May 24, 2025 | 0.05% (0.00048) | 15.04th | v4 (v2025.03.14) |
References (6)
- https://github.com/Checkmarx/Vulnerabilities-Proofs-of-Concept/tree/main/2018/CVE-2018-25110 exploitThird Party Advisory
- https://github.com/advisories/GHSA-p9wx-2529-fp83 Advisory
- https://github.com/markedjs/marked/commit/20bfc106013ed45713a21672ad4a34df94dcd485 patch
- https://github.com/markedjs/marked/issues/1070 issue-trackingIssue TrackingThird Party Advisory
- https://github.com/markedjs/marked/pull/1083 issue-trackingIssue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2018-25110
| Link | Providers | Tags |
|---|---|---|
| https://github.com/Checkmarx/Vulnerabilities-Proofs-of-Concept/tree/main/2018/CVE-2018-25110 | exploitThird Party Advisory | |
| https://github.com/advisories/GHSA-p9wx-2529-fp83 | Advisory | |
| https://github.com/markedjs/marked/commit/20bfc106013ed45713a21672ad4a34df94dcd485 | patch | |
| https://github.com/markedjs/marked/issues/1070 | issue-trackingIssue TrackingThird Party Advisory | |
| https://github.com/markedjs/marked/pull/1083 | issue-trackingIssue TrackingPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-25110 |
Change history (0)
No recorded changes yet.