CVE-2023-28626 is a denial-of-service vulnerability affecting the Comrak Markdown parser, stemming from quadratic parsing issues that allow specially crafted Markdown to consume excessive resources. This vulnerability carries a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity to achieve a complete loss of availability. While no active exploitation or public exploit code is currently known, and community discussion is minimal, users are strongly advised to upgrade to Comrak version 0.17.0 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.17.0CPE matchmatch criteria | cpe:2.3:a:comrak_project:comrak:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.