Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77fj-vx54-gvh7

Опубликовано: 14 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Go Markdown has an Out-of-bounds Read in SmartypantsRenderer

Summary

Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic.

Details

The smartLeftAngle() function in html/smartypants.go:367-376 performs an out-of-bounds slice operation when processing a < character that is not followed by a > character anywhere in the remaining text. https://github.com/gomarkdown/markdown/blob/37c66b85d6ab025ba67a73ba03b7f3ef55859cca/html/smartypants.go#L367-L376 If the length of the slice is lower than its capacity, this leads to an extra byte of data read. If the length equals the capacity, this leads to a panic.

PoC

package main import ( "bytes" "fmt" "github.com/gomarkdown/markdown/html" ) func main() { src := []byte("<a") fmt.Printf("Input: %q (len=%d, cap=%d)\n", src, len(src), cap(src)) var buf bytes.Buffer sp := html.NewSmartypantsRenderer(html.Smartypants) sp.Process(&buf, src) // panics: slice bounds out of range fmt.Printf("Output: %q\n", buf.String()) }

Impact

This vulnerability will lead to a Denial of Service / panic on the processing service.

-- The Datadog Security Team

Пакеты

Наименование

github.com/gomarkdown/markdown

go
Затронутые версииВерсия исправления

< 0.0.0-20260411013819-759bbc3e3207

0.0.0-20260411013819-759bbc3e3207

EPSS

Процентиль: 27%
0.00346
Низкий

7.5 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

CVSS3: 7.5
redhat
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

CVSS3: 7.5
nvd
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

CVSS3: 7.5
msrc
4 месяца назад

github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer

CVSS3: 7.5
debian
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsi ...

EPSS

Процентиль: 27%
0.00346
Низкий

7.5 High

CVSS3

Дефекты

CWE-125