CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fmx4-26r3-wxpf Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 29 Nov 2025 02:00:00 +0000

Type Values Removed Values Added
Description CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns. CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-29T01:23:09.095Z

Reserved: 2024-01-04T18:44:53.108Z

Link: CVE-2024-22051

cve-icon Vulnrichment

Updated: 2024-08-01T22:35:34.693Z

cve-icon NVD

Status : Modified

Published: 2024-01-04T21:15:10.173

Modified: 2025-11-29T02:15:51.067

Link: CVE-2024-22051

cve-icon Redhat

Severity : Important

Publid Date: 2024-01-04T00:00:00Z

Links: CVE-2024-22051 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses