Security: gomarkdown/markdown
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
IsSafeURL computes url[:nPath] before the len(url) >= nPath check, so a 0/1/2-byte URL panics slice-bounds; reached end to end via markdown.ToHTML(..., html.Safelink) on an empty link destination [x]() (unrecoverable DoS; same class as CVE-2026-40890)GHSA-cv23-7vc5-jfh7 published
Jul 25, 2026 by kjkHigh -
Out-of-bounds Read in SmartypantsRendererGHSA-77fj-vx54-gvh7 published
Apr 13, 2026 by kjkHigh -
Multiple XSS vulnerabilities in default configuration (HeadingID injection, fenced code info injection, javascript: URI)GHSA-gc99-qr5c-98ff published
Jul 25, 2026 by kjkCritical -
Out-of-bounds Read while parsing citationsGHSA-m9xq-6h2j-65r2 published
Sep 22, 2023 by kjkModerate
Learn more about advisories related to gomarkdown/markdown in the GitHub Advisory Database