Skip to content

GHSA-253c-mchw-3w2r GHSA-r7fv-28h4-cvq7 markdown-it: Quadratic-time DoS in linkify and smartquotes (14.2.0 -> 14.3.2) - #1151

Merged
vharseko merged 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/markdown-it-14.3.2
Sep 30, 2026
Merged

vharseko merged 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/markdown-it-14.3.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps markdown-it from 14.2.0 to 14.3.2 in openam-ui/openam-ui-ria (package-lock.json only), clearing Dependabot alert #348 for this lock file; the same bump also fixes a second upstream advisory that has no Dependabot alert yet.

Advisories

GHSA-253c-mchw-3w2r (fixed in 14.3.1, no CVE yet) — Uncontrolled resource consumption (CWE-400) through inefficient algorithmic complexity (CWE-407) in the linkify: true handling, in markdown-it's own code rather than in linkify-it. Two independent quadratic paths: the core linkify rule calls arrayReplaceAt once per linkified text token and rebuilds the whole children array each time, so a paragraph of N soft-broken lines with schema-less e-mails costs N rebuilds of a 2N array ('a@b.co\n'.repeat(20000), 273 KB → ~20 s); and the inline linkify rule matches SCHEME_RE against the ever-growing state.pending at every ://, so an unregistered scheme rescans the lot ('a://'.repeat(40000), 156 KB → ~15 s). 14.3.1 backports the 15.0.1 fixes.

GHSA-r7fv-28h4-cvq7 (fixed in 14.3.2, no CVE yet) — Quadratic complexity (CWE-400 / CWE-407) in the smartquotes rule with typographer: true: many opening double quotes followed by unmatched closing single quotes (or the reverse) rescan the whole opener stack every time — '"a '.repeat(k) + "b' ".repeat(k) takes ~1.6 s at 192 KB and grows quadratically. This is a different path from the smartquotes replaceAt issue fixed in 14.2.0 (CVE-2026-48988). 14.3.2 backports the 15.0.2 fix (markdown-it/markdown-it#1209), which also caps the smartquotes stack at 1000 unmatched openers. The advisory is published in the markdown-it repository but has not reached the GitHub Advisory Database yet, hence no Dependabot alert.

Severity Affected (14.x line) Fixed in
GHSA-253c-mchw-3w2r Medium — CVSS 4.0 6.3 (AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N) < 14.3.1 14.3.1
GHSA-r7fv-28h4-cvq7 High — CVSS 3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) < 14.3.2 14.3.2

Both are availability-only: no code execution, no data exposure. Both need an option that is off by default (linkify / typographer).

Impact on OpenAM

None at runtime, none in the build. markdown-it is a transitive development dependency of openam-ui-ria (dev: true): the single copy in the lock file comes from jsdoc 4.0.4 (plus its own markdown-it-anchor), and jsdoc is used only by the manual npm run jsdoc script. The Maven build runs build:production (grunt prod) and test (grunt karma:build), neither of which calls jsdoc; no OpenAM source imports markdown-it and it does not ship in the RIA bundle or the WAR. Even under npm run jsdoc the vulnerable paths are unreachable: jsdoc builds its renderer as new MarkdownIt({ breaks, highlight, html: true }), leaving linkify and typographer at their false defaults, and it renders only the repository's own README.md and doc comments from src/main/js. The bump takes the development toolchain out of the vulnerable range.

Change

The node_modules/markdown-it entry in openam-ui/openam-ui-ria/package-lock.json: 14.2.0 → 14.3.2 (version, resolved, integrity), plus its declared ranges entities ^4.4.0 → ^4.5.0 and linkify-it ^5.0.1 → ^5.0.2. Both are already satisfied by the copies in the lock file (entities 4.5.0, linkify-it 5.0.2 since #1078), so no other entry moves. package.json is untouched — jsdoc@4.0.4 asks for markdown-it@^14.1.0, which 14.3.2 satisfies. No code or behaviour change.

Verified:

  • the lock file integrity matches npm view markdown-it@14.3.2 dist.integrity
  • openam-ui-ria is the only lock file in openam-ui that resolves markdown-it

References

Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.2.0 to 14.3.2.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md)
- [Commits](markdown-it/markdown-it@14.2.0...14.3.2)

---
updated-dependencies:
- dependency-name: markdown-it
  dependency-version: 14.3.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 30, 2026
@vharseko vharseko changed the title Bump markdown-it from 14.2.0 to 14.3.2 in /openam-ui/openam-ui-ria GHSA-253c-mchw-3w2r GHSA-r7fv-28h4-cvq7 markdown-it: Quadratic-time DoS in linkify and smartquotes (14.2.0 -> 14.3.2) Sep 30, 2026
@vharseko vharseko added the security Security fix or hardening (CVE, GHSA, XSS/CSRF/SSRF) label Sep 30, 2026
@vharseko
vharseko merged commit aac035c into master Sep 30, 2026
16 checks passed
@vharseko
vharseko deleted the dependabot/npm_and_yarn/openam-ui/openam-ui-ria/markdown-it-14.3.2 branch September 30, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code security Security fix or hardening (CVE, GHSA, XSS/CSRF/SSRF)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant