CVE-2026-40890High· 7.5▾ TwilightA flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
Last analysed / modified upstream
A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input containing a '<' character not followed by a '>' character, when processed by the SmartypantsRenderer, can lead to an out-of-bounds read or a panic. This can result in a denial of service (DoS) for the application, making it unavailable to legitimate users.
github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input — rated Moderate by Red Hat. Released 2026-04-21, updated 2026-09-21.
Fixed:
Not affected:
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:22347 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:23345 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:24503
Workarounds / mitigations:
Affected packages:
github.com/gomarkdown/markdown < 0.0.0-20260411013819-759bbc3e3207Patched in:
github.com/gomarkdown/markdown 0.0.0-20260411013819-759bbc3e3207Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34040High· 8.4Moby: Moby: Authorization bypass vulnerability (CVE-2026-34040)
CVE-2026-33218High· 7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-27889High· 7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
CVE-2026-25679High· 7.5url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-44244High· 7.3GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration (CVE-2026-44244)
CVE-2026-41293High· 7.3tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293)