markdown parser and HTML renderer for Go
github.com/gomarkdown/[email protected] has vulnerabilities — update to latest
Update to >= 0.0.0-20240729212818-a2a9c4f76ef5 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2026-40890 | Go Markdown has an Out-of-bounds Read in SmartypantsRenderer | 0.0.0-20260411013819-759bbc3e3207 |
| high | CVE-2023-42821 | Markdown vulnerable to Out-of-bounds Read while parsing citations | 0.0.0-20230922105210-14b16010c2ee |
| medium | CVE-2024-44337 | Infinite loop in github.com/gomarkdown/markdown | 0.0.0-20240729212818-a2a9c4f76ef5 |
| unknown | CVE-2023-42821 | Parser out-of-bounds read caused by a malformed markdown input in github.com/gomarkdown/markdown | 0.0.0-20230922105210-14b16010c2ee |
| unknown | CVE-2024-44337 | Infinite loop in github.com/gomarkdown/markdown | 0.0.0-20240729212818-a2a9c4f76ef5 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/github.com/gomarkdown/markdownLast updated · 2026-04-17T12:42:07Z