{"id":"GHSA-4xf9-pgvv-xx67","summary":"Duplicate Advisory: Regular Expression Denial of Service in simple-markdown","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-gpvj-gp8c-c7p2. This link is maintained to preserve external references.\n\n## Original Description\n\nVersions of `simple-markdown` prior to 0.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS). The `SimpleMarkdown.defaultInlineParse()` function has significantly degraded performance when parsing inline code blocks.\n\n\n## Recommendation\n\nUpgrade to version 0.5.2 or later.","modified":"2026-02-03T18:02:39.725158Z","published":"2020-09-03T20:27:46Z","withdrawn":"2026-02-03T17:52:55Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-08-31T18:49:00Z","nvd_published_at":null,"cwe_ids":["CWE-400"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/Khan/simple-markdown/issues/71"},{"type":"WEB","url":"https://github.com/ariabuckles/simple-markdown/commit/89797fef9abb4cab2fb76a335968266a92588816"},{"type":"PACKAGE","url":"https://github.com/Khan/simple-markdown"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-SIMPLEMARKDOWN-460540"}],"affected":[{"package":{"name":"simple-markdown","ecosystem":"npm","purl":"pkg:npm/simple-markdown"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-4xf9-pgvv-xx67/GHSA-4xf9-pgvv-xx67.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}