Unrated severityNVD Advisory· Published Jan 23, 2023· Updated Mar 10, 2025
Inefficient Quadratic complexity bug in handle_pointy_brace may lead to a denial of service
CVE-2023-22484
Description
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to a polynomial time complexity issue in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. This vulnerability has been patched in 0.29.0.gfm.7.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/github/cmark-gfm/security/advisories/GHSA-24f7-9frr-5h2rmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.