markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| markdown2(PyPI) | 1.0.1.18 | 2.4.0 | N/A |
CVSS Metrics