Showdownjs, versions <= 2.1.0, anchors subparser used to parse links has a nested regular expression which can lead to denial of service conditions given malicious input.
{
"cwe_ids": [
"CWE-674",
"CWE-777"
],
"github_reviewed_at": "2026-04-24T20:36:01Z",
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": "2024-02-26T19:15:07Z"
}