{"id":"CVE-2023-31606","details":"A Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem v4.0.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.","aliases":["GHSA-qcm3-vfq5-wfr2"],"modified":"2026-08-12T03:51:12.575517324Z","published":"2023-06-06T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/31xxx/CVE-2023-31606.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/31xxx/CVE-2023-31606.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-31606"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202401-14"},{"type":"REPORT","url":"https://github.com/jgarber/redcloth/issues/73"},{"type":"PACKAGE","url":"https://github.com/e23e/CVE-2023-31606#readme"},{"type":"PACKAGE","url":"https://github.com/jgarber/redcloth"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/07/msg00002.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jgarber/redcloth","events":[{"introduced":"25f3bc3b7f4a67c1bc7d5920cdfd6482540a0108"},{"last_affected":"2ac9f7402f004e75f9b3cc5a841dcc836b786ea9"}],"database_specific":{"cpe":"cpe:2.3:a:promptworks:redcloth:*:*:*:*:*:ruby:*:*","extracted_events":[{"introduced":"4.0.0"},{"last_affected":"4.3.2"}],"source":"CPE_RANGE"}}],"versions":["v4.3.2","v4.3.1","v4.3.0","v4.2.9","v4.2.8","v4.2.7","v4.2.6","v4.2.5","v4.2.4","v4.2.4.pre3","v4.2.4.pre2","v4.2.4.pre1","v4.2.4.pre","RELEASE_4_2_3","RELEASE_4_2_2","RELEASE_4_2_1","RELEASE_4_2_0","RELEASE_4_1_9","RELEASE_4_1_1","RELEASE_4_1_0","RELEASE_4_0_4","RELEASE_4_0_3","RELEASE_4_0_2","RELEASE_4_0_1","RELEASE_4_0_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-31606.json"}}],"schema_version":"1.9.0"}