Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40890

26
FAUCET Score

CVE-2026-40890 is a denial-of-service vulnerability in the gomarkdown/markdown Go library that occurs when the SmartypantsRenderer processes malformed Markdown input containing an unmatched less-than character. The flaw triggers an out-of-bounds read or panic condition, affecting any application using this library to render user-supplied Markdown content. The vulnerability was patched in commit 759bbc3e32073c3bc4e25969c132fc520eda2778. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, characterized by a network-based attack vector requiring no authentication or user interaction and no special access privileges. Exploitation is straightforward due to low attack complexity, needing only submission of malformed input to trigger the condition. The impact is limited to availability, potentially causing application crashes or service disruption without compromising confidentiality or integrity. This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.00038 indicates extremely low probability of exploitation within the next 30 days. Community attention appears minimal given its inactive status on threat intelligence lists, though organizations using the gomarkdown library should apply patches to prevent potential denial-of-service attacks against their services.

Impacted Technologies

VendorProductVersion(s)CPE
< 2026-04-10CPE matchmatch criteria
cpe:2.3:a:gomarkdown:markdown:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.35%
Probability of exploitation in next 30 days
EPSS Percentile
27.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0035 is in the 8th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/gomarkdown/markdownFixed in: 0.0.0-20260411013819-759bbc3e3207
microsoftpatch availablevia msrc
Product: cbl2 cri-o 1.22.3-20 on CBL Mariner 2.0Fixed in: 1.22.3-21
microsoftpatch availablevia msrc
Product: 21187-17086Fixed in: 1.22.3-21

Vendor Advisories (2)

goGHSA-77fj-vx54-gvh7high

Go Markdown has an Out-of-bounds Read in SmartypantsRenderer

Apr 14, 2026
microsoft2026-Apr/CVE-2026-40890Important

github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer

Apr 14, 2026

References

github.com / gomarkdown/markdown/commit/759bbc3e32073c3bc4e25969c132fc520eda2778
Patch
github.com / gomarkdown/markdown/security/advisories/GHSA-77fj-vx54-gvh7
ExploitVendor Advisory