{"id":"CVE-2024-44337","aliases":["GHSA-xhr3-wf7j-h255","GO-2024-3205"],"url":"https://o3.security/vulnerability/CVE-2024-44337","summary":"Infinite loop in github.com/gomarkdown/markdown","details":"The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there was a logical problem in the paragraph function of the parser/block.go file, which allowed a remote attacker to cause a denial of service (DoS) condition by providing a tailor-made input that caused an infinite loop, causing the program to hang and consume resources indefinitely. Submit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252` contains fixes to this problem.","published":"2024-10-15T00:00:00Z","modified":"2026-09-20T03:30:51.725524346Z","cvss":{"score":5.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},"epss":{"score":0.00506,"percentile":0.41084,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/gomarkdown/markdown","fixedVersion":"0.0.0-20240729212818-a2a9c4f76ef5"}],"fix":{"url":"https://github.com/gomarkdown/markdown/commit/a2a9c4f76ef5a5c32108e36f7c47f8d310322252","label":"gomarkdown/markdown@a2a9c4f"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/44xxx/CVE-2024-44337.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-44337"},{"type":"FIX","url":"https://github.com/gomarkdown/markdown/commit/a2a9c4f76ef5a5c32108e36f7c47f8d310322252"},{"type":"PACKAGE","url":"https://github.com/Brinmon/CVE-2024-44337"},{"type":"PACKAGE","url":"https://github.com/gomarkdown/markdown"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-3205"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-20T03:30:51.725524346Z"}}