markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.
"https://github.com/pypa/advisory-database/blob/main/vulns/markdown2/PYSEC-2021-20.yaml"