Comrak is a focused CommonMark parser implementation whose vulnerability profile concentrates in its core markdown-processing product and centers on input-handling weaknesses including cross-site scripting, improper exception handling, and resource-consumption flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Comrak Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28631CRITICAL comrak is a CommonMark + GFM compatible Markdown parser and renderer written in rust. A Comrak AST can be constructed manually by a program instead of parsing a Markdown document w | Mar 28, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-28626HIGH comrak is a CommonMark + GFM compatible Markdown parser and renderer written in rust. A range of quadratic parsing issues are present in Comrak. These can be used to craft denial-o | Mar 28, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-38186MEDIUM An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HTML entities. | Aug 8, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-27671MEDIUM An issue was discovered in the comrak crate before 0.9.1 for Rust. XSS can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for ex | Feb 25, 2021 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Comrak Project.
Media articles that mention a CVE ID that affects a product developed by Comrak Project — matched by CVE ID, not by vendor name.