VDB
CVE-2026-4833
CVE-2026-4833
PUBLISHED
CVSS 1.7000000476837158 LOW
A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled recursion. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project maintainer confirms: "[I]f you feed it an infinitely deep blockquote input it will crash. (...) [T]his is a duplicate of an old bug that I've been working on."
EPSS 0.12% · 2.0th percentile
Risk Scores
CVSS 2.0
1.7000000476837158
EPSS Score
0.12%
2.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Orc | discount | 3.0.1.0, 3.0.1.1, 3.0.1.2 |
Timeline
- Mar 26, 2026 Coalition ESS Score
- Mar 26, 2026 CVE Published
- Mar 26, 2026 PoC Published
- Mar 27, 2026 EPSS Score
- Mar 29, 2026 Security Advisory
- Mar 30, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
References
- VDB-353138 | CTI Indicators (IOB, IOC, IOA) url
- https://github.com/Orc/discount url
- https://github.com/user-attachments/files/25847391/crash00.md url
- Submit #775841 | Orc discount 3.0.1.2 Memory Corruption third-party-advisory
- https://github.com/Orc/discount/ technical
- https://vuldb.com/?id.353138 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-4833 advisory
- https://github.com/Orc/discount/issues/305#issuecomment-4027546673 discussion
- https://github.com/Orc/discount/issues/305 discussion