7.5
CVSSv3

CVE-2023-22486

Published: 26/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions before 0.29.0.gfm.7 contain a polynomial time complexity issue in handle_close_bracket that may lead to unbounded resource exhaustion and subsequent denial of service. This vulnerability has been patched in 0.29.0.gfm.7.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

github cmark-gfm

Vendor Advisories

Debian Bug report logs - #1033110 cmark-gfm: CVE-2023-22483 CVE-2023-22484 CVE-2023-22485 CVE-2023-22486 Package: src:cmark-gfm; Maintainer for src:cmark-gfm is Keith Packard <keithp@keithpcom>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 17 Mar 2023 13:54:04 UTC Severity: important Tags: security, u ...