Critical severity9.8OSV Advisory· Published Jan 4, 2024· Updated Jul 14, 2026
CVE-2024-22051
CVE-2024-22051
Description
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
commonmarkerRubyGems | < 0.23.4 | 0.23.4 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/gjtorikian/commonmarker/commit/ab4504fd17460627a6ab255bc3c63e8e5fc6aed3nvdPatchWEB
- github.com/advisories/GHSA-fmx4-26r3-wxpfnvdThird Party AdvisoryADVISORY
- github.com/gjtorikian/commonmarker/security/advisories/GHSA-fmx4-26r3-wxpfnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-22051ghsaADVISORY
- vulncheck.com/advisories/vc-advisory-GHSA-fmx4-26r3-wxpfnvdThird Party Advisory
- github.com/github/cmark-gfm/security/advisories/GHSA-mc3g-88wq-6f4xnvdNot ApplicableWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/commonmarker/CVE-2024-22051.ymlghsaWEB
News mentions
0No linked articles in our index yet.