{"id":"CVE-2026-40890","title":"github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input (CVE-2026-40890)","summary":"A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-1286","vendor":"Red Hat","product":"Multicluster Global Hub 1.4.9","affected":["multicluster_global_hub 1.4.9","multicluster_global_hub 1.6.5","multicluster_global_hub 1.7.3","advanced_cluster_management_for_kubernetes 2.15","multicluster_global_hub 1.5.3"],"patched":["multicluster_global_hub 1.4.9","multicluster_global_hub 1.6.5","multicluster_global_hub 1.7.3","advanced_cluster_management_for_kubernetes 2.15","multicluster_global_hub 1.5.3"],"published":"2026-04-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:22:00+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40890.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40890.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-40890"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2460245"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-40890"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40890"},{"url":"https://github.com/gomarkdown/markdown/commit/759bbc3e32073c3bc4e25969c132fc520eda2778"},{"url":"https://github.com/gomarkdown/markdown/security/advisories/GHSA-77fj-vx54-gvh7"},{"url":"https://access.redhat.com/errata/RHSA-2026:22347"},{"url":"https://access.redhat.com/errata/RHSA-2026:23345"},{"url":"https://access.redhat.com/errata/RHSA-2026:24503"},{"url":"https://access.redhat.com/errata/RHSA-2026:24539"},{"url":"https://access.redhat.com/errata/RHSA-2026:21769"},{"url":"https://github.com/gomarkdown/markdown"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00515,"epssPercentile":0.41416,"aliases":["GHSA-77fj-vx54-gvh7","GO-2026-5208"],"ecosystem":"go","ingestedAt":"2026-07-25T19:08:11.151Z","slug":"CVE-2026-40890","body":"## Overview\n\nA flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input containing a '<' character not followed by a '>' character, when processed by the SmartypantsRenderer, can lead to an out-of-bounds read or a panic. This can result in a denial of service (DoS) for the application, making it unavailable to legitimate users.\n\n## Vendor advisories\n\n- **RHSA-2026:22347** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22347)\n- **RHSA-2026:23345** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23345)\n- **RHSA-2026:24503** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24503)\n- **RHSA-2026:24539** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24539)\n- **RHSA-2026:21769** · Red Hat · fixed in: Red Hat multicluster global hub 1.5.3 · released 2026-05-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:21769)\n\n**github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input** — rated Moderate by Red Hat. Released 2026-04-21, updated 2026-09-21.\n\nFixed:\n\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.6.5\n- Multicluster Global Hub 1.7.3\n- Red Hat Advanced Cluster Management for Kubernetes 2.15\n- Red Hat multicluster global hub 1.5.3\n\nNot affected:\n\n- Multicluster Global Hub 1.4.9\n- Multicluster Global Hub 1.6.5\n- Multicluster Global Hub 1.7.3\n- Red Hat Advanced Cluster Management for Kubernetes 2.15\n- Red Hat multicluster global hub 1.5.3\n- Kube Descheduler Operator\n\n## Remediation\n\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:22347\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:23345\nFor more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:\n\nhttps://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:24503\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-40890)\n\nAffected packages:\n\n- `github.com/gomarkdown/markdown < 0.0.0-20260411013819-759bbc3e3207`\n\nPatched in:\n\n- `github.com/gomarkdown/markdown 0.0.0-20260411013819-759bbc3e3207`\n\nSource: https://osv.dev/vulnerability/GHSA-77fj-vx54-gvh7","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}