cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 contain a polynomial time complexity issue in handle_close_bracket that may lead to unbounded resource exhaustion and subsequent denial of service. This vulnerability has been patched in 0.29.0.gfm.7.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade cmark | Aug 22, 2024 | Jan 24, 2023 |
| Debian | — | Upgrade cmark-gfmUpgrade ruby-commonmarkerUpgrade python-cmarkgfmUpgrade r-cran-commonmarkNo solution exists | May 15, 2025 | Jan 26, 2023 |
| Suse | — | Upgrade cmark-develUpgrade cmarkUpgrade libcmark0_30_2 | Apr 14, 2023 | Jan 26, 2023 |
| Ubuntu | — | Upgrade cmark-gfmUpgrade cmark-gfm (Ubuntu Pro) | Mar 5, 2025 | Jan 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub