Intel

AIKIDO-2025-10765

comrak is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 31, 2025

22

Low Risk

This Affects:

RUSTcomrak
0.0.1 - 0.45.0
Fixed in 0.46.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to denial-of-service (DoS) attacks due to a stack overflow during footnote resolution. Deeply nested elements could trigger excessive recursion, leading to application crashes. To mitigate this, footnote resolution has been refactored to avoid recursion, and inline footnotes are now limited to a nesting depth of five.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

comrak is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.45.0.

How to fix this

Upgrade the comrak library to the patch version.