VDB
Sign up
MEDIUM5.3

GHSA-xxmq-4vph-956w

Comrak vulnerable to production of excessive output when parsing Markdown (GHSL-2023-048)

Details

### Impact

comrak is vulnerable to the upstream cmark issue, ["Issue revealed by fuzzer"](https://github.com/commonmark/cmark/issues/354). A large number of references in a markdown document can trigger an overly large response.

### Patches

0.17.0 contains https://github.com/kivikakk/comrak/commit/70f97f3ea4eae30ffbd1b94c764a3de2f1c41d2a, which limits reference output to a 100Kb maximum.

### Workarounds

n/a

### References

* https://github.com/commonmark/cmark/issues/354

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/comrak
Introduced in: 0Fixed in: 0.17.0

Upgrade comrak to 0.17.0 or newer (ecosystem crates.io).

References