CVE-2024-22051
Critical · CVSS 9.8commonmarker — Integer overflow leading to heap memory corruption (RCE / information leak)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-190, CWE-190
Description
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.
Search profile — drives PoC discovery
Symbols UINT16_MAXcmark-gfmcommonmarkermarker rowstable columnsab4504fd17460627a6ab255bc3c63e8e5fc6aed3GHSA-fmx4-26r3-wxpfGHSA-mc3g-88wq-6f4x
Keywords CVE-2024-22051commonmarkercmark-gfminteger overflowUINT16_MAXtable marker rowsheap corruptionRCEcommonmarker 0.23.4GHSA-fmx4-26r3-wxpfgjtorikianGitHub Flavored Markdown
Versions: < 0.23.4
Ranked PoCs (2) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0trickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
Affected packages
| RubyGems | commonmarker | 0 → 0.23.4 |
References
- https://github.com/advisories/GHSA-fmx4-26r3-wxpf
- https://github.com/github/cmark-gfm/security/advisories/GHSA-mc3g-88wq-6f4x
- https://github.com/gjtorikian/commonmarker/commit/ab4504fd17460627a6ab255bc3c63e8e5fc6aed3
- https://github.com/gjtorikian/commonmarker/security/advisories/GHSA-fmx4-26r3-wxpf
- https://vulncheck.com/advisories/vc-advisory-GHSA-fmx4-26r3-wxpf
- https://github.com/advisories/GHSA-fmx4-26r3-wxpf
- https://github.com/github/cmark-gfm/security/advisories/GHSA-mc3g-88wq-6f4x
- https://github.com/gjtorikian/commonmarker/commit/ab4504fd17460627a6ab255bc3c63e8e5fc6aed3
- https://github.com/gjtorikian/commonmarker/security/advisories/GHSA-fmx4-26r3-wxpf
- https://vulncheck.com/advisories/vc-advisory-GHSA-fmx4-26r3-wxpf
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z