VYPR
Unrated severityNVD Advisory· Published Jan 24, 2023· Updated Mar 10, 2025

cmark-gfm Quadratic complexity bug in handle_close_bracket may lead to a denial of service

CVE-2023-22486

Description

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomial time complexity issue in handle_close_bracket that may lead to unbounded resource exhaustion and subsequent denial of service. This vulnerability has been patched in 0.29.0.gfm.7.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.