Bugzilla – Bug 1208974
VUL-0: CVE-2023-26303: markdown-it-py: Denial of service by forcing null assertions with specially crafted input
Last modified: 2024-06-10 19:22:43 UTC
CVE-2023-26303 Denial of service could be caused to markdown-it-py, before v2.2.0, if an attacker was allowed to force null assertions with specially crafted input. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-26303 https://bugzilla.redhat.com/show_bug.cgi?id=2175704 https://www.cve.org/CVERecord?id=CVE-2023-26303 http://www.cvedetails.com/cve/CVE-2023-26303/ https://github.com/executablebooks/markdown-it-py/commit/ae03c6107dfa18e648f6fdd1280f5b89092d5d49
Affected: - openSUSE:Factory/python-markdown-it-py
I was assigned but am neither the maintainer nor the bugowner of the affected package. Nevertheless I opened a request https://build.opensuse.org/request/show/1069649 The rest needs to be done by the maintainers.