CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2024-22051

Critical · CVSS 9.8

commonmarker — Integer overflow leading to heap memory corruption (RCE / information leak)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-190, CWE-190

Description

CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.

Search profile — drives PoC discovery

Symbols UINT16_MAXcmark-gfmcommonmarkermarker rowstable columnsab4504fd17460627a6ab255bc3c63e8e5fc6aed3GHSA-fmx4-26r3-wxpfGHSA-mc3g-88wq-6f4x
Keywords CVE-2024-22051commonmarkercmark-gfminteger overflowUINT16_MAXtable marker rowsheap corruptionRCEcommonmarker 0.23.4GHSA-fmx4-26r3-wxpfgjtorikianGitHub Flavored Markdown
Versions: < 0.23.4

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

RubyGems commonmarker 0 → 0.23.4

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z