PatchSiren cyber security CVE debrief
CVE-2015-8854 Fedoraproject CVE debrief
CVE-2015-8854 describes a denial-of-service issue in the Node.js package marked before 0.3.4. The flaw is a regular expression denial of service (ReDoS) caused by catastrophic backtracking in the em inline rule, which can drive CPU consumption high and reduce service availability. The NVD record rates the issue High with CVSS 3.1 base score 7.5.
- Vendor
- Fedoraproject
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-23
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-23
- Advisory updated
- 2026-05-13
Who should care
Teams running marked in Node.js applications, especially where untrusted or user-supplied Markdown is processed. Fedora maintainers and users of packages mapped to the affected Fedora CPEs should also review their package versions and update status.
Technical summary
The supplied CVE record says marked before 0.3.4 is vulnerable to a ReDoS condition in the em inline rule. The weakness is classified as CWE-1333, and the NVD CVSS vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. In practical terms, crafted input can trigger expensive regex processing and consume CPU without requiring privileges or user interaction.
Defensive priority
High. This is a remotely reachable availability issue with no privileges or user interaction required, and the primary impact is service slowdown or outage through CPU exhaustion.
Recommended defensive actions
- Inventory applications and dependencies that use marked and confirm whether any version earlier than 0.3.4 is present.
- Upgrade marked to 0.3.4 or later, or replace it with a maintained alternative if upgrade support is uncertain.
- Review any services that accept untrusted Markdown and apply input validation, request throttling, and resource controls where feasible.
- Monitor for abnormal CPU spikes or latency tied to Markdown parsing paths.
- For Fedora environments, verify whether the affected package builds referenced by the CVE record have been updated in your distribution channels.
Evidence notes
This debrief is based on the supplied CVE description and NVD metadata. The record states: marked before 0.3.4 is vulnerable; the issue is a catastrophic backtracking problem in the em inline rule; the weakness is CWE-1333; and the CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The supplied metadata also lists Fedora 31 and 32 CPE entries and references third-party advisories, including one broken-link advisory entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2015-8854 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2015-8854
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2015-8854 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2015-8854
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO2RMVVZVV6NFTU46B5RYRK7ZCXYARZS/
[email protected] - Mailing List, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M6BJG6RGDH7ZWVVAUFBFI5L32RSMQN2S/
[email protected] - Mailing List, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://nodesecurity.io/advisories/23
[email protected] - Broken Link, Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.