GHSA-4qw4-jpp4-8gvp
Unbounded resource exhaustion in cmark-gfm autolink extension may lead to denial of service
Quick fix
GHSA-4qw4-jpp4-8gvp — commonmarker: upgrade to the fixed version with the command below.
bundle update commonmarkerDetails
### Impact
CommonMarker uses `cmark-gfm` for rendering [Github Flavored Markdown](https://github.github.com/gfm/). A polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.
### Patches
This vulnerability has been patched in the following CommonMarker release:
- v0.23.6
### Workarounds
Disable use of the autolink extension.
### References
https://github.com/gjtorikian/commonmarker/pull/190 https://github.com/github/cmark-gfm/security/advisories/GHSA-cgh3-p57x-9q7q https://en.wikipedia.org/wiki/Time_complexity
### For more information If you have any questions or comments about this advisory: * Open an issue in [github/cmark-gfm](https://github.com/github/cmark-gfm)
### Acknowledgements
We would like to thank [Legit Security](https://www.legitsecurity.com) for reporting this vulnerability.
Are you affected?
Enter the version of the package you're using.