md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion failure) via a malformed Markdown document.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26148
Reference (s):
- https://github.com/mity/md4c/issues/130

