CVE-2026-35201 is a signed length truncation vulnerability affecting the Discount Markdown parser (C implementation) in versions 1.3.1.1 through 2.2.7.4. The flaw causes an out-of-bounds read when processing inputs larger than INT_MAX, as these values are truncated to a signed integer before parsing, allowing the parser to read beyond the allocated buffer and crash the process. The vulnerability carries a CVSS severity score of 5.9 (Medium) with a network-based attack vector requiring high complexity to exploit. While the attack requires no user interaction or privileges, the impact is limited to denial of service through process crashes; there is no confidentiality or integrity compromise. The EPSS score of 0.0005 indicates this is among the lower-probability vulnerabilities for real-world exploitation. There is currently no evidence of active exploitation, with the vulnerability not appearing on CISA's Known Exploited Vulnerabilities (KEV) catalog or security hot lists. The modest FAUCET risk score of 43/100 and low EPSS percentile suggest minimal community attention and low likelihood of weaponization at this time. Organizations running vulnerable Discount versions should update to 2.2.7.4 or later as part of routine patch management.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.1.1, < 2.2.7.4CPE matchmatch criteria | cpe:2.3:a:dafoster:rdiscount:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.