CVE-2023-26485 describes a polynomial time complexity vulnerability in cmark-gfm, GitHub's fork of the cmark CommonMark parsing library, affecting versions prior to 0.29.0.gfm.10. This denial-of-service (DoS) vulnerability, rated High severity (CVSS 7.5), allows an unauthenticated attacker to cause unbounded resource exhaustion by submitting specially crafted input containing a large number of underscore characters. While there is no evidence of active exploitation or public exploit code, the issue can lead to significant service disruption. Users are strongly advised to upgrade to the patched version or validate input from trusted sources.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.29.0.gfm.10CPE matchmatch criteria | cpe:2.3:a:github:cmark-gfm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.