{"id":"GHSA-48wp-p9qv-4j64","aliases":[],"url":"https://o3.security/vulnerability/GHSA-48wp-p9qv-4j64","summary":"Commonmarker vulnerable to to several quadratic complexity bugs that may lead to denial of service","details":"## Impact\n\nSeveral quadratic complexity bugs in commonmarker's underlying [`cmark-gfm`](https://github.com/github/cmark-gfm) library may lead to unbounded resource exhaustion and subsequent denial of service.\n\nThe following vulnerabilities were addressed:\n\n* [CVE-2023-24824](https://github.com/github/cmark-gfm/security/advisories/GHSA-66g8-4hjf-77xh)\n* [CVE-2023-26485](https://github.com/github/cmark-gfm/security/advisories/GHSA-r8vr-c48j-fcc5)\n\nFor more information, consult the release notes for version [`0.23.0.gfm.10`](https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.10) and [`0.23.0.gfm.11`](https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.11).\n\n## Mitigation\n\nUsers are advised to upgrade to commonmarker version [`0.23.9`](https://rubygems.org/gems/commonmarker/versions/0.23.9).","published":"2023-04-11T22:08:18Z","modified":"2024-12-04T05:41:10.781623Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"commonmarker","fixedVersion":"0.23.9"}],"fix":{"url":"https://github.com/gjtorikian/commonmarker/pull/236","label":"gjtorikian/commonmarker#236"},"references":[{"type":"WEB","url":"https://github.com/github/cmark-gfm/security/advisories/GHSA-66g8-4hjf-77xh"},{"type":"WEB","url":"https://github.com/github/cmark-gfm/security/advisories/GHSA-r8vr-c48j-fcc5"},{"type":"WEB","url":"https://github.com/gjtorikian/commonmarker/security/advisories/GHSA-48wp-p9qv-4j64"},{"type":"WEB","url":"https://github.com/gjtorikian/commonmarker/pull/236"},{"type":"WEB","url":"https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.10"},{"type":"WEB","url":"https://github.com/github/cmark-gfm/releases/tag/0.29.0.gfm.11"},{"type":"PACKAGE","url":"https://github.com/gjtorikian/commonmarker"},{"type":"WEB","url":"https://github.com/gjtorikian/commonmarker/releases/tag/v0.23.9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:41:10.781623Z"}}