{"id":"DEBIAN-CVE-2022-39209","details":"cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running `python3 -c 'print(\"![l\"* 100000 + \"\\n\")' | ./cmark-gfm -e autolink`, which will resource exhaust on unpatched cmark-gfm but render correctly on patched cmark-gfm. This vulnerability has been patched in 0.29.0.gfm.6. Users are advised to upgrade. Users unable to upgrade should disable the use of the autolink extension.","modified":"2026-09-01T16:05:27.135753038Z","published":"2022-09-15T18:15:12.260Z","upstream":["CVE-2022-39209"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-39209"}],"affected":[{"package":{"name":"cmark-gfm","ecosystem":"Debian:12","purl":"pkg:deb/debian/cmark-gfm?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.29.0.gfm.6-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"cmark-gfm","ecosystem":"Debian:13","purl":"pkg:deb/debian/cmark-gfm?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.29.0.gfm.6-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"cmark-gfm","ecosystem":"Debian:14","purl":"pkg:deb/debian/cmark-gfm?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.29.0.gfm.6-2"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"ghostwriter","ecosystem":"Debian:12","purl":"pkg:deb/debian/ghostwriter?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.6+ds-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"ghostwriter","ecosystem":"Debian:13","purl":"pkg:deb/debian/ghostwriter?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.6+ds-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"ghostwriter","ecosystem":"Debian:14","purl":"pkg:deb/debian/ghostwriter?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.6+ds-1"}]}],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"python-cmarkgfm","ecosystem":"Debian:12","purl":"pkg:deb/debian/python-cmarkgfm?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.0-3","2024.11.20-1","2025.10.22-1","2025.10.22-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"python-cmarkgfm","ecosystem":"Debian:13","purl":"pkg:deb/debian/python-cmarkgfm?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2024.11.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"python-cmarkgfm","ecosystem":"Debian:14","purl":"pkg:deb/debian/python-cmarkgfm?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2024.11.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"r-cran-commonmark","ecosystem":"Debian:12","purl":"pkg:deb/debian/r-cran-commonmark?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"r-cran-commonmark","ecosystem":"Debian:13","purl":"pkg:deb/debian/r-cran-commonmark?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"r-cran-commonmark","ecosystem":"Debian:14","purl":"pkg:deb/debian/r-cran-commonmark?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.1-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"ruby-commonmarker","ecosystem":"Debian:12","purl":"pkg:deb/debian/ruby-commonmarker?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.23.10-1","0.23.6-1","0.23.9-1","2.8.3-1","2.8.3-2","2.8.3-3","2.8.3-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"ruby-commonmarker","ecosystem":"Debian:13","purl":"pkg:deb/debian/ruby-commonmarker?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}},{"package":{"name":"ruby-commonmarker","ecosystem":"Debian:14","purl":"pkg:deb/debian/ruby-commonmarker?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.23.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-39209.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}