{"id":"CVE-2026-40890","aliases":["GHSA-77fj-vx54-gvh7","GO-2026-5208"],"url":"https://o3.security/vulnerability/CVE-2026-40890","summary":"github.com/gomarkdown/markdown: Out-of-bounds Read in SmartypantsRenderer","details":"The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.","published":"2026-04-21T19:51:53.237Z","modified":"2026-08-07T03:30:32.625882776Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/gomarkdown/markdown","fixedVersion":"0.0.0-20260411013819-759bbc3e3207"}],"fix":{"url":"https://github.com/gomarkdown/markdown/commit/759bbc3e32073c3bc4e25969c132fc520eda2778","label":"gomarkdown/markdown@759bbc3"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40890.json"},{"type":"ADVISORY","url":"https://github.com/gomarkdown/markdown/security/advisories/GHSA-77fj-vx54-gvh7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40890"},{"type":"FIX","url":"https://github.com/gomarkdown/markdown/commit/759bbc3e32073c3bc4e25969c132fc520eda2778"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T03:30:32.625882776Z"}}