Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

markdown2 malformed HTML tokenizer CPU denial of service

未关闭
#707 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
55/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
冷清
技术栈
python
领域
security

调研方向

从 lib/markdown2.py 中的 _sorta_html_tokenize_re.split() 开始,使用附带的 proof of concept 通过 bash ./poc/run.sh 重现该问题。检查标签分支的正则表达式,并验证格式错误的片段不再触发一秒超时,同时保留预期的 HTML 标记化行为。

由索引模型根据 Issue 内容生成。

描述

Bug

Describe the bug
python-markdown2 can spend unbounded CPU in its inline HTML tokenizer when rendering attacker-controlled Markdown containing repeated malformed tag fragments. At the pinned commit, the public markdown2.markdown() path can pass that text to _sorta_html_tokenize_re.split() in lib/markdown2.py, and a roughly 60 KB input deterministically reaches the local one-second timeout oracle. Applications that render untrusted Markdown synchronously can therefore have request workers tied up by a single document.

To Reproduce
INT-regex-markdown2-html-tokenizer-redos.zip

See attached file.

bash ./poc/run.sh
timed_out after 1s

Expected behavior
Tag-branch regex fails to match the malformed fragment in linear time.

Debug info

For more details, see README.md of attached file.

主要语言
Python
星标
2.8k
派生
459
平均合并
2 天 19 小时
30 天内合并 PR
4

贡献指南

这个仓库没有索引到贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

trentm/python-markdown2 的其他 Issue

查看 trentm/python-markdown2 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。