cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
References
Link | Resource |
---|---|
https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.12 | Release Notes |
https://github.com/github/cmark-gfm/security/advisories/GHSA-w4qg-3vf7-m9x5 | Exploit |
Configurations
History
No history.
Information
Published : 2023-07-13 20:15
Updated : 2023-07-25 18:37
NVD link : CVE-2023-37463
Mitre link : CVE-2023-37463
CVE.ORG link : CVE-2023-37463
JSON object : View
Products Affected
github
- cmark-gfm
CWE