Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40890

Опубликовано: 21 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The package github.com/gomarkdown/markdown is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input containing a '<' character not followed by a '>' character, when processed by the SmartypantsRenderer, can lead to an out-of-bounds read or a panic. This can result in a denial of service (DoS) for the application, making it unavailable to legitimate users.

Отчет

This is an Important denial of service flaw affecting Red Hat products that utilize the github.com/gomarkdown/markdown library. The vulnerability occurs when the SmartypantsRenderer processes specially crafted malformed Markdown input containing an unclosed '<' character, leading to an out-of-bounds read or application panic. A successful exploitation may lead the application using the library unavailable.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Kube Descheduler Operatorkube-descheduler-operator/descheduler-rhel9Not affected
Kube Descheduler Operatorkube-descheduler-operator/descheduler-rhel9Not affected
Multicluster Global Hub 1.4.5multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2234701.06.2026
Multicluster Global Hub 1.6.2multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2334504.06.2026
Multicluster Global Hub 1.7.0multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2450308.06.2026
Red Hat Advanced Cluster Management for Kubernetes 2.15rhacm2/acm-grafana-rhel9FixedRHSA-2026:2453908.06.2026
Red Hat multicluster global hub 1.5.2multicluster-globalhub/multicluster-globalhub-grafana-rhel9FixedRHSA-2026:2176928.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2460245github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input

EPSS

Процентиль: 27%
0.00346
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

CVSS3: 7.5
nvd
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

CVSS3: 7.5
msrc
4 месяца назад

github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer

CVSS3: 7.5
debian
4 месяца назад

The package `github.com/gomarkdown/markdown` is a Go library for parsi ...

CVSS3: 7.5
github
4 месяца назад

Go Markdown has an Out-of-bounds Read in SmartypantsRenderer

EPSS

Процентиль: 27%
0.00346
Низкий

7.5 High

CVSS3