Improper Handling of Alternate Encoding
CVE-2023-26303
Summary
Denial-of-service attack could be caused to markdown-it-py in versions prior to 2.2.0, if an attacker was allowed to force null assertions with specially crafted input.
- LOW
- LOCAL
- NONE
- UNCHANGED
- NONE
- LOW
- NONE
- HIGH
CWE-173 - Improper Handling of Alternate Encoding
The software does not properly handle when an input uses an alternate encoding that is valid for the control sphere to which the input is being sent.
References
Advisory Timeline
- Published