CVE-2024-22051
CWE-190Published: January 4, 2024· Updated: Jul 14, 2026
Official Description
CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result in possibly unauthenticated remote attackers to cause heap memory corruption, potentially leading to an information leak or remote code execution, via parsing tables with marker rows that contain more than UINT16_MAX columns.
Risk Analysis
CommonMarker is susceptible to an integer overflow during the parsing of tables with an excessive number of columns. This can lead to heap memory corruption, potentially resulting in remote code execution or information disclosure.
There are no known public exploits for this issue, and it is not in the CISA KEV. The vulnerability is remotely exploitable without authentication.
Upgrade to CommonMarker version 0.23.4 or later to resolve the integer overflow. Ensure that input parsing is restricted to prevent processing of malicious table structures.
Technical Analysis
CVE-2024-22051 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 9.8.
CVSS v3.1 Vector Breakdown
Affected Vendors & Products
Exploit & PoC Resources
Official Patches & Advisories
All References (10)
Quick Facts
Related CVEs (CWE-190)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2024-22051 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts