Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22051


CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.


Published

2024-01-04T21:15:10.173

Last Modified

2025-11-29T02:15:51.067

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-190
  • Type: Primary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application github cmark-gfm < 0.28.3.gfm.21 Yes
Application github cmark-gfm < 0.29.0.gfm.3 Yes
Application gjtorikian commonmarker < 0.23.4 Yes

References