Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40890

Опубликовано: 21 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The package github.com/gomarkdown/markdown is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gomarkdown:markdown:*:*:*:*:*:go:*:*
Версия до 2026-04-10 (исключая)

EPSS

Процентиль: 27%
0.00346
Низкий

7.5 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

CVSS3: 7.5
redhat
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

CVSS3: 7.5
msrc
4 месяца назад

github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer

CVSS3: 7.5
debian
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsi ...

CVSS3: 7.5
github
4 месяца назад

Go Markdown has an Out-of-bounds Read in SmartypantsRenderer

EPSS

Процентиль: 27%
0.00346
Низкий

7.5 High

CVSS3

Дефекты

CWE-125