---
id: CVE-2026-40890
title: >-
  github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of
  Service via malformed Markdown input (CVE-2026-40890)
summary: >-
  A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing
  Markdown text and rendering as HTML. A remote attacker could exploit this
  vulnerability by providing a specially crafted malformed input. Specifically,
  input cont…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-1286
vendor: Red Hat
product: Multicluster Global Hub 1.4.9
affected:
  - multicluster_global_hub 1.4.9
  - multicluster_global_hub 1.6.5
  - multicluster_global_hub 1.7.3
  - advanced_cluster_management_for_kubernetes 2.15
  - multicluster_global_hub 1.5.3
patched:
  - multicluster_global_hub 1.4.9
  - multicluster_global_hub 1.6.5
  - multicluster_global_hub 1.7.3
  - advanced_cluster_management_for_kubernetes 2.15
  - multicluster_global_hub 1.5.3
published: '2026-04-21'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:22:00+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40890.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40890.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-40890'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2460245'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-40890'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-40890'
  - url: >-
      https://github.com/gomarkdown/markdown/commit/759bbc3e32073c3bc4e25969c132fc520eda2778
  - url: >-
      https://github.com/gomarkdown/markdown/security/advisories/GHSA-77fj-vx54-gvh7
  - url: 'https://access.redhat.com/errata/RHSA-2026:22347'
  - url: 'https://access.redhat.com/errata/RHSA-2026:23345'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24503'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24539'
  - url: 'https://access.redhat.com/errata/RHSA-2026:21769'
  - url: 'https://github.com/gomarkdown/markdown'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00515
epssPercentile: 0.41416
aliases:
  - GHSA-77fj-vx54-gvh7
  - GO-2026-5208
ecosystem: go
ingestedAt: '2026-07-25T19:08:11.151Z'
---

## Overview

A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input containing a '<' character not followed by a '>' character, when processed by the SmartypantsRenderer, can lead to an out-of-bounds read or a panic. This can result in a denial of service (DoS) for the application, making it unavailable to legitimate users.

## Vendor advisories

- **RHSA-2026:22347** · Red Hat · fixed in: Multicluster Global Hub 1.4.9 · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22347)
- **RHSA-2026:23345** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23345)
- **RHSA-2026:24503** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24503)
- **RHSA-2026:24539** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24539)
- **RHSA-2026:21769** · Red Hat · fixed in: Red Hat multicluster global hub 1.5.3 · released 2026-05-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:21769)

**github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input** — rated Moderate by Red Hat. Released 2026-04-21, updated 2026-09-21.

Fixed:

- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.6.5
- Multicluster Global Hub 1.7.3
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat multicluster global hub 1.5.3

Not affected:

- Multicluster Global Hub 1.4.9
- Multicluster Global Hub 1.6.5
- Multicluster Global Hub 1.7.3
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat multicluster global hub 1.5.3
- Kube Descheduler Operator

## Remediation

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:22347
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.15/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:23345
For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:

https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.16/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:24503

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-40890)

Affected packages:

- `github.com/gomarkdown/markdown < 0.0.0-20260411013819-759bbc3e3207`

Patched in:

- `github.com/gomarkdown/markdown 0.0.0-20260411013819-759bbc3e3207`

Source: https://osv.dev/vulnerability/GHSA-77fj-vx54-gvh7
