GHSA-253c-mchw-3w2r GHSA-r7fv-28h4-cvq7 markdown-it: Quadratic-time DoS in linkify and smartquotes (14.2.0 -> 14.3.2) - #1151
Merged
vharseko merged 1 commit intoSep 30, 2026
Conversation
Bumps [markdown-it](https://github.com/markdown-it/markdown-it) from 14.2.0 to 14.3.2. - [Changelog](https://github.com/markdown-it/markdown-it/blob/14.3.2/CHANGELOG.md) - [Commits](markdown-it/markdown-it@14.2.0...14.3.2) --- updated-dependencies: - dependency-name: markdown-it dependency-version: 14.3.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
vharseko
approved these changes
Sep 30, 2026
vharseko
deleted the
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/markdown-it-14.3.2
branch
September 30, 2026 15:50
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps
markdown-itfrom 14.2.0 to 14.3.2 inopenam-ui/openam-ui-ria(package-lock.jsononly), clearing Dependabot alert #348 for this lock file; the same bump also fixes a second upstream advisory that has no Dependabot alert yet.Advisories
GHSA-253c-mchw-3w2r (fixed in 14.3.1, no CVE yet) — Uncontrolled resource consumption (CWE-400) through inefficient algorithmic complexity (CWE-407) in the
linkify: truehandling, in markdown-it's own code rather than inlinkify-it. Two independent quadratic paths: the core linkify rule callsarrayReplaceAtonce per linkified text token and rebuilds the wholechildrenarray each time, so a paragraph of N soft-broken lines with schema-less e-mails costs N rebuilds of a 2N array ('a@b.co\n'.repeat(20000), 273 KB → ~20 s); and the inline linkify rule matchesSCHEME_REagainst the ever-growingstate.pendingat every://, so an unregistered scheme rescans the lot ('a://'.repeat(40000), 156 KB → ~15 s). 14.3.1 backports the 15.0.1 fixes.GHSA-r7fv-28h4-cvq7 (fixed in 14.3.2, no CVE yet) — Quadratic complexity (CWE-400 / CWE-407) in the smartquotes rule with
typographer: true: many opening double quotes followed by unmatched closing single quotes (or the reverse) rescan the whole opener stack every time —'"a '.repeat(k) + "b' ".repeat(k)takes ~1.6 s at 192 KB and grows quadratically. This is a different path from the smartquotesreplaceAtissue fixed in 14.2.0 (CVE-2026-48988). 14.3.2 backports the 15.0.2 fix (markdown-it/markdown-it#1209), which also caps the smartquotes stack at 1000 unmatched openers. The advisory is published in the markdown-it repository but has not reached the GitHub Advisory Database yet, hence no Dependabot alert.AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N)AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)Both are availability-only: no code execution, no data exposure. Both need an option that is off by default (
linkify/typographer).Impact on OpenAM
None at runtime, none in the build.
markdown-itis a transitive development dependency ofopenam-ui-ria(dev: true): the single copy in the lock file comes fromjsdoc4.0.4 (plus its ownmarkdown-it-anchor), andjsdocis used only by the manualnpm run jsdocscript. The Maven build runsbuild:production(grunt prod) andtest(grunt karma:build), neither of which callsjsdoc; no OpenAM source importsmarkdown-itand it does not ship in the RIA bundle or the WAR. Even undernpm run jsdocthe vulnerable paths are unreachable:jsdocbuilds its renderer asnew MarkdownIt({ breaks, highlight, html: true }), leavinglinkifyandtypographerat theirfalsedefaults, and it renders only the repository's ownREADME.mdand doc comments fromsrc/main/js. The bump takes the development toolchain out of the vulnerable range.Change
The
node_modules/markdown-itentry inopenam-ui/openam-ui-ria/package-lock.json: 14.2.0 → 14.3.2 (version,resolved,integrity), plus its declared rangesentities^4.4.0→^4.5.0andlinkify-it^5.0.1→^5.0.2. Both are already satisfied by the copies in the lock file (entities4.5.0,linkify-it5.0.2 since #1078), so no other entry moves.package.jsonis untouched —jsdoc@4.0.4asks formarkdown-it@^14.1.0, which 14.3.2 satisfies. No code or behaviour change.Verified:
integritymatchesnpm view markdown-it@14.3.2 dist.integrityopenam-ui-riais the only lock file inopenam-uithat resolvesmarkdown-itReferences