CVE-2026-40890 is a denial-of-service vulnerability in the gomarkdown/markdown Go library that occurs when the SmartypantsRenderer processes malformed Markdown input containing an unmatched less-than character. The flaw triggers an out-of-bounds read or panic condition, affecting any application using this library to render user-supplied Markdown content. The vulnerability was patched in commit 759bbc3e32073c3bc4e25969c132fc520eda2778. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, characterized by a network-based attack vector requiring no authentication or user interaction and no special access privileges. Exploitation is straightforward due to low attack complexity, needing only submission of malformed input to trigger the condition. The impact is limited to availability, potentially causing application crashes or service disruption without compromising confidentiality or integrity. This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.00038 indicates extremely low probability of exploitation within the next 30 days. Community attention appears minimal given its inactive status on threat intelligence lists, though organizations using the gomarkdown library should apply patches to prevent potential denial-of-service attacks against their services.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-04-10CPE matchmatch criteria | cpe:2.3:a:gomarkdown:markdown:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.