CVE-2024-22051
Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption
8.8
HIGH
CVSS 3.1
EPSS 1.5%
Description
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.
How to fix CVE-2024-22051
To remediate CVE-2024-22051, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 0.23.4 or later
Is CVE-2024-22051 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0
- from 0, < 0.23.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |