This advisory has been withdrawn, per NVD: "This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue."
A Regular expression Denial of Service (ReDoS) vulnerability in the file marked.js of the marked npm package (tested on version 0.3.7) allows a remote attacker to overload and crash a server by passing a maliciously crafted string.
{
"github_reviewed": true,
"severity": "MODERATE",
"github_reviewed_at": "2020-06-16T21:32:51Z",
"nvd_published_at": null,
"cwe_ids": []
}