CVE-2023-22483
CVE-2023-22483 is a low-severity vulnerability in Github Cmark-gfm with a CVSS 3.x base score of 3.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-407.
Key facts
- Severity: Low (CVSS 3.x base score 3.5)
- EPSS exploit prediction: 1% (63rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-407
- Affected product: Github Cmark-gfm
- Published:
- Last modified:
Description
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to several polynomial time complexity issues in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. Various commands, when piped to cmark-gfm with large values, cause the running time to increase quadratically. These vulnerabilities have been patched in version 0.29.0.gfm.7.
Frequently asked questions
- What is CVE-2023-22483?
- cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. Versions prior to 0.29.0.gfm.7 are subject to several polynomial time complexity issues in cmark-gfm that may lead to unbounded resource exhaustion and subsequent denial of service. Various commands, when piped to cmark-gfm with large values, cause the running time to increase quadratically. These vulnerabilities have been patched in version 0.29.0.gfm.7.
- How severe is CVE-2023-22483?
- CVE-2023-22483 has a CVSS 3.x base score of 3.5, rated low severity. It is exploitable over an adjacent network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2023-22483 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (63rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-22483?
- CVE-2023-22483 affects Github Cmark-gfm. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-22483?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-22483 published?
- CVE-2023-22483 was published on 2023-01-23 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:github:cmark-gfm:*:*:*:*:*:*:*:*
More vulnerabilities in Github Cmark-gfm
- CVE-2024-22051 — Critical (CVSS 9.8): CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability. This vulnerability can result…
- CVE-2022-24724 — High (CVSS 8.8): cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3…
- CVE-2022-39209 — High (CVSS 7.5): cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to…
- CVE-2023-37463 — Medium (CVSS 6.4): cmark-gfm is an extended version of the C reference implementation of CommonMark, a rationalized version of Markdown…
- CVE-2023-26485 — Medium (CVSS 5.3): cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time…
- CVE-2023-24824 — Medium (CVSS 5.3): cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time…
All CVEs affecting Github Cmark-gfm →
Other CWE-407 vulnerabilities
- CVE-2026-49250 — High (CVSS 8.7): Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From…
- CVE-2026-83613 — High (CVSS 8.7): xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to…
- CVE-2026-75596 — High (CVSS 8.7): Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the…
- CVE-2026-54284 — High (CVSS 8.7): sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion…
- CVE-2026-65623 — High (CVSS 8.7): Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via…
- CVE-2026-57480 — High (CVSS 8.7): Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to…