GHSA-4r62-v4vq-hr96 · Severity: medium · Ecosystem: npm — Regular Expression Denial of Service (REDoS) in Marked
Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regular expression Denial of Service vulnerability. This vulnerability can affect anyone who runs user generated code through marked. This vulnerability is fixed in version 2.0.0.
Conclusion & alert: CVE-2021-21306 is rated Moderate Risk (51.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.46%). Core evidence: EPSS rose +1.86% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.60% | 2.46% | +1.86% |
| 2 | 2025-03-30 | 1.69% | 0.60% | -1.09% |
| 3 | 2025-03-29 | — | 1.69% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-4r62-v4vq-hr96 · Severity: medium · Ecosystem: npm — Regular Expression Denial of Service (REDoS) in Marked
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2021-21306 unimportant priority: Debian including 1 source packages (node-marked), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-21306 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-21306 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| marked_project | marked | >= 1.1.1, < 2.0.0 | cpe:2.3:a:marked_project:marked:*:*:*:*:*:node.js:*:* |
| URL | Tags |
|---|---|
| https://github.com/markedjs/marked/commit/7293251c438e3ee968970f7609f1a27f9007bccd | Patch Third Party Advisory |
| https://github.com/markedjs/marked/issues/1927 | Third Party Advisory |
| https://github.com/markedjs/marked/pull/1864 | Patch Third Party Advisory |
| https://github.com/markedjs/marked/security/advisories/GHSA-4r62-v4vq-hr96 | Third Party Advisory |
| https://www.npmjs.com/package/marked | Product Third Party Advisory |