CVE-2022-39209
HIGHEPSS 81th pctlDescription
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service. Users may verify the patch by running `python3 -c 'print("](https://tridentstack.com/cve/CVE-2022-39209)HTML
<a href="https://tridentstack.com/cve/CVE-2022-39209"><img src="https://tridentstack.com/cve/badge/CVE-2022-39209.svg" alt="CVE-2022-39209"></a>Check your Linux endpoints for this class of vulnerability
TridentStack Control continuously scans Linux endpoints for known vulnerabilities and deploys the fixes from the same console. 200 endpoints free forever, no credit card.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-06-17.