cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing text which leads with either large numbers of `>` or `-` characters. This issue has been addressed in version 0.29.0.gfm.10. Users are advised to upgrade. Users unable to upgrade should validate that their input comes from trusted sources.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Fri, 06 Jun 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat Redhat enterprise Linux | |
| CPEs | cpe:/a:redhat:enterprise_linux:8::crb | |
| Vendors & Products | Redhat Redhat enterprise Linux | 
Tue, 11 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-03-31T22:01:18.220Z
Updated: 2025-02-11T17:19:40.510Z
Reserved: 2023-01-30T14:43:33.705Z
Link: CVE-2023-24824
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T11:03:19.254Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-03-31T23:15:07.153
Modified: 2024-11-21T07:48:28.123
Link: CVE-2023-24824
 Redhat
                        Redhat