CVE-2023-22486

Name
CVE-2023-22486
Description
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomial time complexity issue in handle_close_bracket that may lead to unbounded resource exhaustion and subsequent denial of service. This vulnerability has been patched in 0.29.0.gfm.7.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/github/cmark-gfm/security/advisories/GHSA-r572-jvj2-3m8p

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:github:cmark-gfm:*:*:*:*:*:*:*:* cmark-gfm >= None < 0.29.0.gfm.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
cmark 3.17-community 0.30.3-r0 Bart Ribbers <bribbers@disroot.org> fixed