# sonatype-2018-0076

## Marked - Regular Expression Denial Of Service (REDOS)

**Published:** May 24, 2018  
**CVSS Score:** Medium (6.5)

## Security Details

### CVE ID
**sonatype-2018-0076**  
**CWE:** N/A

### CVE Description
**Marked - Regular Expression Denial Of Service (REDOS)**  
**Published:** May 24, 2018

### CVSS Score & Severity
**6.5 Medium**  
**CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H  
**EPSS Score:** 0%

### Malware
**Status:** Not in KEV Catalog: No known exploits

### Affected Ecosystems
**Source:** Sonatype

## References
- [Sonatype Blog](https://blog.sonatype.com/cve-2017-17461-vulnerable-or-not "https://blog.sonatype.com/cve-2017-17461-vulnerable-or-not") - EVIDENCE  
- [GitHub · PR #1224](https://github.com/markedjs/marked/pull/1224 "https://github.com/markedjs/marked/pull/1224") - PROJECT  
- [GitHub · Issue #404](https://github.com/raml2html/raml2html/issues/404 "https://github.com/raml2html/raml2html/issues/404") - PROJECT
