Skip to main content
HIGH

CVE-2018-18385

CVSS v3

7.5

HIGH

EPSS Score

2.3 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Asciidoctor in versions < 1.5.8 allows remote attackers to cause a denial of service (infinite loop). The loop was caused by the fact that Parser.next_block was not exhausting all the lines in the reader as the while loop expected it would. This was happening because the regular expression that detects any list was not agreeing with the regular expression that detects a specific list type. So the line kept getting pushed back onto the reader, hence causing the loop.

Technical details

Published
2018-10-16

Frequently asked questions

What is CVE-2018-18385?

Asciidoctor in versions < 1.5.8 allows remote attackers to cause a denial of service (infinite loop). The loop was caused by the fact that Parser.next_block was not exhausting all the lines in the reader as the while loop expected it would. This was happening because the regular expression that detects any list was not agreeing with the regular expression that detects a specific list type. So the line kept getting pushed back onto the reader, hence causing the loop.

Is CVE-2018-18385 actively exploited?

Active exploitation of CVE-2018-18385 has not been confirmed. Its EPSS score was 2.3% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-18385?

CVE-2018-18385 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2018-18385 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key