Redcarpet is a Markdown parser library with a narrow but notably embedded footprint in Ruby-based applications and documentation systems. Its vulnerability profile centers on the core product and recurs through application-layer weaknesses characteristic of text parsing and HTML generation, namely cross-site scripting, injection flaws, and buffer-boundary issues that arise from unsafe handling of untrusted markup input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redcarpet Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-5147HIGH Stack-based buffer overflow in the header_anchor function in the HTML renderer in Redcarpet before 3.3.2 allows attackers to cause a denial of service (crash) and possibly execute | Jul 14, 2015 | 7.5 | 21 | NO | NO |
CVE-2020-26298MEDIUM Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affec | Jan 11, 2021 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redcarpet Project.
Media articles that mention a CVE ID that affects a product developed by Redcarpet Project — matched by CVE ID, not by vendor name.