First published: Thu Jul 13 2023(Updated: )
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Github Cmark-gfm | <0.29.0.gfm.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37463 is a vulnerability in cmark-gfm, an extended version of the C reference implementation of CommonMark.
CVE-2023-37463 has a severity rating of 7.5, which is considered high.
CVE-2023-37463 affects cmark-gfm version 0.29.0.gfm.12 and earlier.
To fix CVE-2023-37463, update cmark-gfm to version 0.29.0.gfm.13 or later.
You can find more information about CVE-2023-37463 on the GitHub security advisory page and the GitHub release page for cmark-gfm version 0.29.0.gfm.12.