{"id":"CVE-2021-21306","details":"Marked is an open-source markdown parser and compiler (npm package \"marked\"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.","aliases":["GHSA-4r62-v4vq-hr96"],"modified":"2026-04-12T01:01:14.694546Z","published":"2021-02-08T22:15:12.450Z","related":["GHSA-4r62-v4vq-hr96"],"references":[{"type":"ADVISORY","url":"https://github.com/markedjs/marked/issues/1927"},{"type":"ADVISORY","url":"https://github.com/markedjs/marked/security/advisories/GHSA-4r62-v4vq-hr96"},{"type":"ADVISORY","url":"https://www.npmjs.com/package/marked"},{"type":"FIX","url":"https://github.com/markedjs/marked/commit/7293251c438e3ee968970f7609f1a27f9007bccd"},{"type":"FIX","url":"https://github.com/markedjs/marked/pull/1864"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/markedjs/marked","events":[{"introduced":"1ad8e69e9b959d0be03e6a345767daad28993f5d"},{"fixed":"8a7502f54fcc236027ae38e5432c4caf30accf23"},{"fixed":"7293251c438e3ee968970f7609f1a27f9007bccd"}],"database_specific":{"source":["CPE_FIELD","REFERENCES"],"cpe":"cpe:2.3:a:marked_project:marked:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"1.1.1"},{"fixed":"2.0.0"}]}}],"versions":["v1.1.1","v1.1.2","v1.2.1","v1.2.2","v1.2.3","v1.2.4","v1.2.5","v1.2.6","v1.2.7","v1.2.8","v1.2.9","v1.20"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-21306.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}