Gomarkdown is a focused markdown-processing library with a narrow product footprint but notable visibility in document-rendering and text-conversion workflows. Its disclosed vulnerabilities center on memory-safety weaknesses, particularly out-of-bounds reads that arise from parser edge cases in markdown syntax handling; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gomarkdown over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40890HIGH The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not foll | Apr 21, 2026 | 7.5 | 26 | NO | NO |
CVE-2023-42821HIGH The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `0.0.0-20230922105210-14b16010c2ee`, which corr | Sep 22, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gomarkdown.
Media articles that mention a CVE ID that affects a product developed by Gomarkdown — matched by CVE ID, not by vendor name.