CVE-2026-4833 describes an uncontrolled recursion vulnerability in the Markdown Handler component of Orc discount up to version 3.0.1.2, specifically within the `compile` function of `markdown.c`. This flaw can be triggered by processing deeply nested blockquote inputs, leading to a denial of service. Rated with a CVSS score of 3.3 LOW, exploitation requires local access and low privileges, impacting system availability. Although an exploit has been publicly disclosed, there is no indication of active exploitation, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Orc | Discount | 3.0.1.0, 3.0.1.1, 3.0.1.2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.