Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-28631

30
FAUCET Score

CVE-2023-28631 is a critical vulnerability affecting the comrak CommonMark and GFM compatible Markdown parser and renderer. It arises when a manually constructed Abstract Syntax Tree (AST) contains malformed data, specifically non-UTF-8 byte arrays, which the HTML formatting code incorrectly assumes to be valid. This can lead to severe impacts including data confidentiality, integrity, and availability compromises. Rated with a CVSS score of 9.8 (Critical), this vulnerability is remotely exploitable with low attack complexity and no user interaction required. The FAUCET Risk Score is 78/100, indicating a high potential risk. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, which is typical for a large percentage of CVEs.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.17.0CPE matchmatch criteria
cpe:2.3:a:comrak_project:comrak:*:*:*:*:*:rust:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.27%
Probability of exploitation in next 30 days
EPSS Percentile
66.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0127 is in the 53rd percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
rustpatch availablevia ghsa
Product: comrakFixed in: 0.17.0

Vendor Advisories (1)

rustGHSA-5r3x-p7xx-x6q5medium

Comrak AST node data is not validated (GHSL-2023-049)

Mar 28, 2023

References

github.com / kivikakk/comrak/commit/9ff5f8df0ac951f5742d22a72c39b89a15f56639
Patch
github.com / kivikakk/comrak/security/advisories/GHSA-5r3x-p7xx-x6q5
Vendor Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/OUYME2VA555X6567H7ORIJQFN4BVGT6N
lists.fedoraproject.org / archives/list/[email protected]/message/PTWZWCT7KCX2KTXTLPUYZ3EHOONG4X46
lists.fedoraproject.org / archives/list/[email protected]/message/VQ3UBC7LE4VPCMZBTADIBL353CH7CPVV