top of page
perceptive_background_267k.jpg

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < charac…

Published:

20 April 2026 at 22:00:00

Alert date:

21 April 2026 at 21:04:31

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

The github.com/gomarkdown/markdown Go library contains a vulnerability that causes out-of-bounds memory reads or panics when processing malformed input. The issue occurs when the SmartypantsRenderer processes text containing a '<' character not followed by a '>' character anywhere in the remaining text. This can lead to memory safety issues including out-of-bounds reads or application crashes. The vulnerability has been patched in commit 759bbc3e32073c3bc4e25969c132fc520eda2778. Organizations using this Go markdown parsing library should update to the fixed version to prevent potential denial of service attacks.

Technical details

Mitigation steps:

Affected products:

github.com/gomarkdown/markdown

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page