Medium severity6.4NVD Advisory· Published Jul 13, 2023· Updated Jun 17, 2026
CVE-2023-37463
CVE-2023-37463
Description
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords4 versionspkg:deb/ubuntu/cmark-gfm@0.29.0.gfm.0-4?arch=source&distro=focalpkg:deb/ubuntu/cmark-gfm@0.29.0.gfm.3-3?arch=source&distro=jammypkg:deb/ubuntu/cmark-gfm@0.29.0.gfm.6-6build1?arch=source&distro=noblepkg:deb/ubuntu/cmark-gfm@0.29.0.gfm.6-6build1?arch=source&distro=oracular
>= 0+ 3 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.