{"id":"DEBIAN-CVE-2023-26485","details":"cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing text which leads with either large numbers of `_` characters. This issue has been addressed in version 0.29.0.gfm.10. Users are advised to upgrade. Users unable to upgrade should validate that their input comes from trusted sources.     ### Impact  A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service.  ### Proof of concept  ``` $ ~/cmark-gfm$ python3 -c 'pad = \"_\" * 100000; print(pad + \".\" + pad, end=\"\")' | time ./build/src/cmark-gfm --to plaintext ```  Increasing the number 10000 in the above commands causes the running time to increase quadratically.  ### Patches  This vulnerability have been patched in 0.29.0.gfm.10.  ### Note on cmark and cmark-gfm  XXX: TBD  [cmark-gfm](https://github.com/github/cmark-gfm) is a fork of [cmark](https://github.com/commonmark/cmark) that adds the GitHub Flavored Markdown extensions. The two codebases have diverged over time, but share a common core. These bugs affect both `cmark` and `cmark-gfm`.   ### Credit  We would like to thank @gravypod for reporting this vulnerability.  ### References  https://en.wikipedia.org/wiki/Time_complexity  ### For more information  If you have any questions or comments about this advisory:  * Open an issue in [github/cmark-gfm](https://github.com/github/cmark-gfm)","modified":"2026-09-15T09:01:22.214966288Z","published":"2023-03-31T23:15:07.250Z","upstream":["CVE-2023-26485"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2023-26485"}],"affected":[{"package":{"name":"cmark-gfm","ecosystem":"Debian:12","purl":"pkg:deb/debian/cmark-gfm?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.29.0.gfm.13-1","0.29.0.gfm.13-2","0.29.0.gfm.13-3","0.29.0.gfm.13-4","0.29.0.gfm.13-7","0.29.0.gfm.13-7.1","0.29.0.gfm.6-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"cmark-gfm","ecosystem":"Debian:13","purl":"pkg:deb/debian/cmark-gfm?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.29.0.gfm.13-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"cmark-gfm","ecosystem":"Debian:14","purl":"pkg:deb/debian/cmark-gfm?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.29.0.gfm.13-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"python-cmarkgfm","ecosystem":"Debian:12","purl":"pkg:deb/debian/python-cmarkgfm?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.0-3","2024.11.20-1","2025.10.22-1","2025.10.22-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"python-cmarkgfm","ecosystem":"Debian:13","purl":"pkg:deb/debian/python-cmarkgfm?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2024.11.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"python-cmarkgfm","ecosystem":"Debian:14","purl":"pkg:deb/debian/python-cmarkgfm?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2024.11.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"r-cran-commonmark","ecosystem":"Debian:12","purl":"pkg:deb/debian/r-cran-commonmark?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.8.1-1","1.9.0-1","1.9.1-1","1.9.2-1","1.9.2-2","1.9.5-1","2.0.0-1","2.0.0-2","2.0.0-3"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"r-cran-commonmark","ecosystem":"Debian:13","purl":"pkg:deb/debian/r-cran-commonmark?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"r-cran-commonmark","ecosystem":"Debian:14","purl":"pkg:deb/debian/r-cran-commonmark?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"ruby-commonmarker","ecosystem":"Debian:12","purl":"pkg:deb/debian/ruby-commonmarker?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.23.10-1","0.23.6-1","0.23.9-1","2.10.0-1","2.10.0-2","2.8.3-1","2.8.3-2","2.8.3-3","2.8.3-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"ruby-commonmarker","ecosystem":"Debian:13","purl":"pkg:deb/debian/ruby-commonmarker?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}},{"package":{"name":"ruby-commonmarker","ecosystem":"Debian:14","purl":"pkg:deb/debian/ruby-commonmarker?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-26485.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}