Security Advisory

CVE-2026-41680

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-24 17:26:27
Last updated 2026-04-24 19:08:41
Assigner GitHub_M
CVSS score 8.7
State PUBLISHED

Description

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memory allocation, causing the host Node.js application to crash via Memory Exhaustion (OOM). This vulnerability is fixed in 18.0.2.