CVE Feed

    Dashboard / CVE / CVE-2022-39209

    CVE-2022-39209

    cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running `python3 -c 'print("![l"* 100000 + "\n")' | ./cmark-gfm -e autolink`, which will resource exhaust on unpatched cmark-gfm but render correctly on patched cmark-gfm. This vulnerability has been patched in 0.29.0.gfm.6. Users are advised to upgrade. Users unable to upgrade should disable the use of the autolink extension.

    Published:Sep 15, 2022
    Last Modified:Apr 23, 2025
    EPS:Sep 15, 2022
    EPSS Score:0.0088
    CVSS Score:7.5

    Affected Products

    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Github
    Product
    Cmark-gfm

    Exploits

    No exploit reference

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-39209 — Fedoraproject, Github (High 7.5) | CVE-DB