<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:17:33 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0933 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</link>
      <description>certfr-2026-avi-0933</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0933</guid>
    </item>
    <item>
      <title>EUVD-2026-328613</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-328613</link>
      <description>EUVD-2026-328613</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-328613</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48988</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48988</link>
      <description>&lt;p&gt;markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per quote character. This can cause excessive CPU consumption when parsing quote-heavy, user-supplied markdown and may let attackers degrade or disrupt service availability. Although typographer is disabled by default, many production apps enable it for smart typography, making the issue relevant. This issue has been fixed in version 14.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per quote character. This can cause excessive CPU consumption when parsing quote-heavy, user-supplied markdown and may let attackers degrade or disrupt service availability. Although typographer is disabled by default, many production apps enable it for smart typography, making the issue relevant. This issue has been fixed in version 14.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48988</guid>
    </item>
    <item>
      <title>GHSA-6v5v-wf23-fmfq — markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6v5v-wf23-fmfq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: markdown-it&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A quadratic time complexity vulnerability exists in markdown-it&amp;#39;s smartquotes rule (enabled via the `typographer: true` option). An attacker can craft a markdown input consisting of consecutive quotation marks that causes the parser to consume excessive CPU time, leading to denial of service.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability is in the `replaceAt()` helper function used by the smartquotes rule in `lib/rules_core/smartquotes.mjs`:&lt;/p&gt;
&lt;p&gt;```javascript
function replaceAt (str, index, ch) {
  return str.slice(0, index) + ch + str.slice(index + 1)
}
```&lt;/p&gt;
&lt;p&gt;When markdown-it processes a text token containing many quotation marks (either `&amp;#34;` or `&amp;#39;`) with `typographer: true`, the smartquotes rule iterates through each quote character and calls `replaceAt()` to substitute it with a typographic (curly) quote. Each call to `replaceAt()` creates three new string slices and concatenates them, which is an O(n) operation where n is the length of the string.&lt;/p&gt;
&lt;p&gt;Since this is called once per quote character in the token, and there are n quote characters, the total time complexity becomes O(n^2).&lt;/p&gt;
&lt;p&gt;The root cause is that the smartquotes rule modifies `token.content` in place using string slicing rather than building the result incrementally. The `process_inlines()` function (line 14) processes each quote in the text token, and for matching quote pairs, calls `replaceAt()` on both the opening and closing token&amp;#39;s content (lines 151-152). When the entire input is a single text token of quote cha…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: markdown-it&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A quadratic time complexity vulnerability exists in markdown-it&amp;#39;s smartquotes rule (enabled via the `typographer: true` option). An attacker can craft a markdown input consisting of consecutive quotation marks that causes the parser to consume excessive CPU time, leading to denial of service.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability is in the `replaceAt()` helper function used by the smartquotes rule in `lib/rules_core/smartquotes.mjs`:&lt;/p&gt;
&lt;p&gt;```javascript
function replaceAt (str, index, ch) {
  return str.slice(0, index) + ch + str.slice(index + 1)
}
```&lt;/p&gt;
&lt;p&gt;When markdown-it processes a text token containing many quotation marks (either `&amp;#34;` or `&amp;#39;`) with `typographer: true`, the smartquotes rule iterates through each quote character and calls `replaceAt()` to substitute it with a typographic (curly) quote. Each call to `replaceAt()` creates three new string slices and concatenates them, which is an O(n) operation where n is the length of the string.&lt;/p&gt;
&lt;p&gt;Since this is called once per quote character in the token, and there are n quote characters, the total time complexity becomes O(n^2).&lt;/p&gt;
&lt;p&gt;The root cause is that the smartquotes rule modifies `token.content` in place using string slicing rather than building the result incrementally. The `process_inlines()` function (line 14) processes each quote in the text token, and for matching quote pairs, calls `replaceAt()` on both the opening and closing token&amp;#39;s content (lines 151-152). When the entire input is a single text token of quote cha…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6v5v-wf23-fmfq</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-48988</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48988</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-markdown-it, Ubuntu:24.04:LTS: node-markdown-it, Ubuntu:25.10: node-markdown-it, Ubuntu:26.04:LTS: node-markdown-it&lt;/p&gt;
&lt;p&gt;markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per quote character. This can cause excessive CPU consumption when parsing quote-heavy, user-supplied markdown and may let attackers degrade or disrupt service availability. Although typographer is disabled by default, many production apps enable it for smart typography, making the issue relevant. This issue has been fixed in version 14.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: node-markdown-it, Ubuntu:24.04:LTS: node-markdown-it, Ubuntu:25.10: node-markdown-it, Ubuntu:26.04:LTS: node-markdown-it&lt;/p&gt;
&lt;p&gt;markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per quote character. This can cause excessive CPU consumption when parsing quote-heavy, user-supplied markdown and may let attackers degrade or disrupt service availability. Although typographer is disabled by default, many production apps enable it for smart typography, making the issue relevant. This issue has been fixed in version 14.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48988</guid>
    </item>
  </channel>
</rss>
