VDB

CVE-2026-4833

CVE-2026-4833 PUBLISHED CVSS 1.7000000476837158 LOW

A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled recursion. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project maintainer confirms: "[I]f you feed it an infinitely deep blockquote input it will crash. (...) [T]his is a duplicate of an old bug that I've been working on."

EPSS 0.12% · 2.0th percentile

Risk Scores

CVSS 2.0
1.7000000476837158
EPSS Score
0.12%
2.0th percentile

Affected Products

VendorProductVersions
Orcdiscount3.0.1.0, 3.0.1.1, 3.0.1.2

Timeline

  • Mar 26, 2026 Coalition ESS Score
  • Mar 26, 2026 CVE Published
  • Mar 26, 2026 PoC Published
  • Mar 27, 2026 EPSS Score
  • Mar 29, 2026 Security Advisory
  • Mar 30, 2026 CVE Updated
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›