pypi package report

Is markdown2 safe?

4 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
2.2%

chance of exploitation in the next 30 days

xyz score
4.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-jr9p-r423-9m2r, the advisory selected below

// advisories

GHSA-jr9p-r423-9m2r

HIGHCVE-2021-26813

markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.

Affected
>= 1.0.1.18, < 2.4.0
Fixed in
2.4.0
Weakness
CWE-1333
Published
2021-06-02
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereference


// dependencies

3 direct, 1 carrying known advisories, worst CRITICAL

Sign in for dependency paths and remediation

// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 00:42 UTC. The most recent advisory here was published 2022-04-21. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is markdown2 safe? pypi package security report | CyberXYZ