CVE-2023-37463: GitHub Cmark-Gfm
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown syntax with a spec. Three polynomial time complexity issues in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. These vulnerabilities have been patched in 0.29.0.gfm.12.
Affected products
- GitHub Cmark-Gfm: before 0.29.0.gfm.12 (fixed in 0.29.0.gfm.12)
Published 2023-07-13. Last modified 2026-06-17.