The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message causing the server to spend an effectively arbitrary amount of CPU time and stall the processing of future messages.
Score: 0.0
Priority: Unclassified
Score: 0.00514
Percentile:
0.65571
CVSS v3.1 Score: 6.5
Severity: MEDIUM