Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35201

24
FAUCET Score

CVE-2026-35201 is a signed length truncation vulnerability affecting the Discount Markdown parser (C implementation) in versions 1.3.1.1 through 2.2.7.4. The flaw causes an out-of-bounds read when processing inputs larger than INT_MAX, as these values are truncated to a signed integer before parsing, allowing the parser to read beyond the allocated buffer and crash the process. The vulnerability carries a CVSS severity score of 5.9 (Medium) with a network-based attack vector requiring high complexity to exploit. While the attack requires no user interaction or privileges, the impact is limited to denial of service through process crashes; there is no confidentiality or integrity compromise. The EPSS score of 0.0005 indicates this is among the lower-probability vulnerabilities for real-world exploitation. There is currently no evidence of active exploitation, with the vulnerability not appearing on CISA's Known Exploited Vulnerabilities (KEV) catalog or security hot lists. The modest FAUCET risk score of 43/100 and low EPSS percentile suggest minimal community attention and low likelihood of weaponization at this time. Organizations running vulnerable Discount versions should update to 2.2.7.4 or later as part of routine patch management.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.3.1.1, < 2.2.7.4CPE matchmatch criteria
cpe:2.3:a:dafoster:rdiscount:*:*:*:*:*:ruby:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 2nd percentile among its peer group of 19,956 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: cbl2 rubygem-rdiscount 2.2.0.2-3 on CBL Mariner 2.0Fixed in: 2.2.0.2-4
microsoftpatch availablevia msrc
Product: azl3 rubygem-rdiscount 2.2.7.1-1 on Azure Linux 3.0Fixed in: 2.2.7.4-1
microsoftpatch availablevia msrc
Product: 21089-17086Fixed in: 2.2.0.2-4
microsoftpatch availablevia msrc
Product: 21088-17084Fixed in: 2.2.7.4-1
rubygemspatch availablevia ghsa
Product: rdiscountFixed in: 2.2.7.4
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

microsoft2026-Apr/CVE-2026-35201Moderate

Discount has an Out-of-bounds Read in rdiscount

Apr 14, 2026
rubygemsGHSA-6r34-94wq-jhrcmedium

rdiscount has an Out-of-bounds Read

Apr 6, 2026

References

github.com / davidfstr/rdiscount/security/advisories/GHSA-6r34-94wq-jhrc
ExploitVendor Advisory