CVE-2023-24824 is a denial-of-service vulnerability affecting GitHub's cmark-gfm library, a CommonMark parsing and rendering tool. This flaw, rated High severity with a CVSS score of 7.5, stems from a polynomial time complexity issue that can be triggered by parsing text with numerous '>' or '-' characters, leading to unbounded resource exhaustion. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Users are advised to upgrade to version 0.29.0.gfm.10 or validate input from trusted sources if upgrading is not immediately possible.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.29.0.gfm.10.CPE matchmatch criteria | cpe:2.3:a:github:cmark-gfm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.