markdown2 malformed HTML tokenizer CPU denial of service
还没有人认领这个 Issue。
评估
调研方向
从 lib/markdown2.py 中的 _sorta_html_tokenize_re.split() 开始,使用附带的 proof of concept 通过 bash ./poc/run.sh 重现该问题。检查标签分支的正则表达式,并验证格式错误的片段不再触发一秒超时,同时保留预期的 HTML 标记化行为。
由索引模型根据 Issue 内容生成。
描述
Describe the bug
python-markdown2 can spend unbounded CPU in its inline HTML tokenizer when rendering attacker-controlled Markdown containing repeated malformed tag fragments. At the pinned commit, the public markdown2.markdown() path can pass that text to _sorta_html_tokenize_re.split() in lib/markdown2.py, and a roughly 60 KB input deterministically reaches the local one-second timeout oracle. Applications that render untrusted Markdown synchronously can therefore have request workers tied up by a single document.
To Reproduce
INT-regex-markdown2-html-tokenizer-redos.zip
See attached file.
bash ./poc/run.sh
timed_out after 1s
Expected behavior
Tag-branch regex fails to match the malformed fragment in linear time.
Debug info
- Project: markdown2
- Repo: https://github.com/trentm/python-markdown2
- Pinned ref: 28d94df671eb2a149643310513f84bb00a084072
For more details, see README.md of attached file.
- 主要语言
- Python
- 星标
- 2.8k
- 派生
- 459
- 平均合并
- 2 天 19 小时
- 30 天内合并 PR
- 4
贡献指南
这个仓库没有索引到贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
trentm/python-markdown2 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
trentm/python-markdown2#696 ·
-
难度 4/5 3-5 天 新手友好度 48/100
trentm/python-markdown2#726 ·
-
Bug
难度 3/5 1-2 天 新手友好度 58/100
trentm/python-markdown2#688 · 4 条评论 ·
-
Bug
难度 3/5 1-2 天 新手友好度 58/100
trentm/python-markdown2#679 · 2 条评论 ·
-
难度 3/5 1-2 天 新手友好度 35/100
trentm/python-markdown2#635 · 2 条评论 ·
查看 trentm/python-markdown2 的全部 Issue
相似的 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 75/100
stephrobert/dsoxlab#238 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 75/100
sublimehq/package_control#1780 ·
-
难度 2/5 1-3 小时 新手友好度 65/100
-
难度 2/5 1-3 小时 新手友好度 70/100
nwg-piotr/nwg-displays#145 ·