CVE-2026-35201Disclosure(dafoster / rdiscount)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dafoster rdiscount systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than INT_MAX are truncated to a signed int before entering the native parser, allowing the parser to read past the end of the supplied buffer and crash the process. This vulnerability is fixed in 2.2.7.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rdiscount

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
rdiscount

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-06: 1Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-17: 104-0604-17
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-061
Disclosure1
2026-04-171
Patch1
Full discourse2 posts
  • WindowsForum@windowsforum
    Patch

    🚨 CVE-2026-35201 is the ultimate “Markdown can ruin your day” bug: feed it enough text past INT_MAX and the parser faceplants. Fix = 2.2.7.4—because uptime matters. https://windowsforum.com/threads/cve-2026-35201-rdiscount-crash-dos-fixed-in-2-2-7-4-guard-against-int_max.413966/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #DenialOfService #Cve202635201 #Rdiscount #MarkdownParser

    Post summary

    The post highlights CVE‑2026‑35201, a Denial‑of‑Service bug in the Markdown parser triggered by oversized input, and notes that version 2.2.7.4 includes a fix.

    0000041
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35201 Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed length truncation bug causes an out-of-bounds r… https://www.cve.org/CVERecord?id=CVE-2026-35201

    Post summary

    The post announces a signed length truncation bug in the Discount Markdown parser (CVE-2026-35201) that can lead to out‑of‑bounds reads, without mentioning PoC, exploit code, or a patch.

    00000138
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdafosterrdiscount-ruby-

Explore more