Описание
The package github.com/gomarkdown/markdown is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.
A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input containing a '<' character not followed by a '>' character, when processed by the SmartypantsRenderer, can lead to an out-of-bounds read or a panic. This can result in a denial of service (DoS) for the application, making it unavailable to legitimate users.
Отчет
This is an Important denial of service flaw affecting Red Hat products that utilize the github.com/gomarkdown/markdown library. The vulnerability occurs when the SmartypantsRenderer processes specially crafted malformed Markdown input containing an unclosed '<' character, leading to an out-of-bounds read or application panic. A successful exploitation may lead the application using the library unavailable.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Kube Descheduler Operator | kube-descheduler-operator/descheduler-rhel9 | Not affected | ||
| Kube Descheduler Operator | kube-descheduler-operator/descheduler-rhel9 | Not affected | ||
| Multicluster Global Hub 1.4.5 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Fixed | RHSA-2026:22347 | 01.06.2026 |
| Multicluster Global Hub 1.6.2 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Fixed | RHSA-2026:23345 | 04.06.2026 |
| Multicluster Global Hub 1.7.0 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Fixed | RHSA-2026:24503 | 08.06.2026 |
| Red Hat Advanced Cluster Management for Kubernetes 2.15 | rhacm2/acm-grafana-rhel9 | Fixed | RHSA-2026:24539 | 08.06.2026 |
| Red Hat multicluster global hub 1.5.2 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Fixed | RHSA-2026:21769 | 28.05.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.
The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.
github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer
The package `github.com/gomarkdown/markdown` is a Go library for parsi ...
Go Markdown has an Out-of-bounds Read in SmartypantsRenderer
EPSS
7.5 High
CVSS3