rdiscount
Fast Implementation of Gruber's Markdown in C
Activity
- Latest release
- 4mo ago
- Total releases
- 35
- Cadence
- ~40 days
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- BSD-3-Clause
- First release
- Jun 03, 2008
| Version | Released | |
|---|---|---|
2.2.7.5
patch
| ||
2.2.7.4
patch
| ||
2.2.7.3
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.2.7.2
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.2.7.1
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.2.7
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.2.0.2
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.2.0.1
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.1.8
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.1.7.1
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.1.7
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.1.6
minor
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.0.7.3
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.0.7.2
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.0.7.1
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
2.0.7
major
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.6.8
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.6.5
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.6.3.2
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.6.3.1
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.6.3
minor
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.5.8.1
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.5.8
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.5.5
minor
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.3.5
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.3.4
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.3.1.1
patch
1 CVE
CVE-2026-35201
GHSA-6r34-94wq-jhrc
Apr 06, 2026
rdiscount has an Out-of-bounds Read
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
SummaryA signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than DetailsIn both public entry points:
The parser stores the remaining input length in a signed
The read loop stops only when
If the Ruby string length exceeds Affected APIs:
PoCCrash via
result:
same result with ImpactThis is an out-of-bounds read with the main issue being reliable denial-of-service. Impacted is limited to deployments parses attacker-controlled Markdown and permits multi-GB inputs. Fixjust add a checked length guard before the
The same guard should be applied in Affected versions
1.3.1.1
1.3.4
1.3.5
1.5.5
1.5.8
1.5.8.1
1.6.3
1.6.3.1
1.6.3.2
1.6.5
1.6.8
2.0.7
+ 14 more Show less
2.0.7.1
2.0.7.2
2.0.7.3
2.1.6
2.1.7
2.1.7.1
2.1.8
2.2.0
2.2.0.1
2.2.0.2
2.2.7
2.2.7.1
2.2.7.2
2.2.7.3
Fixed in
2.2.7.4
References
Updated May 13, 2026 · Source: OSV.dev | ||
1.3.1
minor
| ||
1.2.11
patch
| ||
1.2.10
patch
| ||
1.2.9
patch
| ||
1.2.7.1
patch
| ||
1.2.7
patch
| ||
1.2.6.2
initial
|