Junglewise Threat Intelligence

CVE-2026-86303: 92181 markdown out-of-bounds read in lds function

CVE-2026-86303 · Severity: high · CVSS 7.3 · Published 2026-09-07

Technologies: 92181 Markdown.

Executive brief

92181 markdown is a high-performance markdown-to-HTML parser written in C. A flaw in the lds() function can allow remote attackers to read memory beyond buffer boundaries, potentially exposing sensitive data or causing the parser to crash when processing specially crafted markdown input.

Technical details

The vulnerability is an out-of-bounds read in the lds() function of md.c, a static inline helper function used during markdown parsing. The flaw occurs when processing exact-length input at buffer boundaries, allowing reads past the intended buffer limits. The attack is network-accessible, requiring only maliciously crafted markdown input; no authentication or user interaction is required. An attacker can exploit this to read adjacent memory contents or trigger denial of service. A patch (commit c000d2f9cf390c315378d3717cf20911cf3e80a6) has been released and should be applied immediately.

Affected products

  • 92181 markdown up to commit 058cab0cb7fb245a0ccc6b8446963ff8d573558f

Timeline

  • 2026-09-07: disclosed: CVE-2026-86303 published
  • 2026-09-07: patched: Fix merged in commit c000d2f9cf390c315378d3717cf20911cf3e80a6

References