Unrated severityNVD Advisory· Published Jan 24, 2023· Updated Mar 10, 2025
cmark-gfm Quadratic complexity bug in handle_close_bracket may lead to a denial of service
CVE-2023-22486
Description
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomial time complexity issue in handle_close_bracket that may lead to unbounded resource exhaustion and subsequent denial of service. This vulnerability has been patched in 0.29.0.gfm.7.
Affected products
5- osv-coords4 versionspkg:rpm/opensuse/cmark&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/cmark&distro=openSUSE%20Tumbleweedpkg:rpm/suse/cmark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP4pkg:rpm/suse/cmark&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4
< 0.30.2-150400.3.3.1+ 3 more
- (no CPE)range: < 0.30.2-150400.3.3.1
- (no CPE)range: < 0.30.3-1.1
- (no CPE)range: < 0.30.2-150400.3.3.1
- (no CPE)range: < 0.30.2-150400.3.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/github/cmark-gfm/security/advisories/GHSA-r572-jvj2-3m8pmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.