Web: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39209

Sept. 15, 2022, 6:15 p.m. |

National Vulnerability Database nist.gov

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running `python3 -c 'print("![l"* 100000 + "\n")' | ./cmark-gfm -e autolink`, which will resource exhaust on unpatched cmark-gfm but render correctly on patched cmark-gfm. This vulnerability has been patched in 0.29.0.gfm.6. Users are …

cve fedora

Chief Information Security Officer

@ Los Angeles Unified School District | Los Angeles

Cybersecurity Engineer

@ Apercen Partners LLC | Folsom, CA

IDM Sr. Security Developer

@ The Ohio State University | Columbus, OH, United States

IT Security Engineer

@ Stylitics | New York City

Information Security Engineer

@ VDA Labs | Remote

Information Security Analyst

@ Metropolitan Transportation Commission | San Francisco, CA

Director of Threat Intelligence

@ McDonald's Corporation | Chicago, IL, United States

Senior Principal Security Engineer - EMEA, Remote

@ GoDaddy | EMEA

Network Security Engineer (Starlink)

@ SpaceX | Redmond, WA, United States

Staff, Cloud Security Engineer

@ Twilio | Remote - US

Senior DevSecOps Engineer

@ Ginger | Remote - United States

Sr Professional Consultant I (Top Secret Clearance)

@ Palo Alto Networks | Las Vegas, NV, United States