<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:13:03 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:8427 — Moderate: pandoc security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:8427</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pandoc, AlmaLinux:8: pandoc-common&lt;/p&gt;
&lt;p&gt;Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. It can read several dialects of Markdown and (subsets of) HTML, reStructuredText, LaTeX, DocBook, JATS, MediaWiki markup, TWiki markup, TikiWiki markup, Creole 1.0, Haddock markup, OPML, Emacs Org-Mode, Emacs Muse, txt2tags, Vimwiki, Word Docx, ODT, and Textile, and it can write Markdown, reStructuredText, XHTML, HTML 5, LaTeX, ConTeXt, DocBook, JATS, OPML, TEI, OpenDocument, ODT, Word docx, RTF, MediaWiki, DokuWiki, ZimWiki, Textile, groff man, groff ms, plain text, Emacs Org-Mode, AsciiDoc, Haddock markup, EPUB (v2 and v3), FictionBook2, InDesign ICML, Muse, LaTeX beamer slides, PowerPoint, and several kinds of HTML/JavaScript slide shows (S5, Slidy, Slideous, DZSlides, reveal.js). In contrast to most existing tools for converting Markdown to HTML, pandoc has a modular design: it consists of a set of readers, which parse text in a given format and produce a native representation of the document, and a set of writers, which convert this native representation into a target format. Thus, adding an input or output format requires only adding a reader or writer. For pdf output please also install pandoc-pdf.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cmark-gfm: Quadratic complexity bugs may lead to a denial of service (CVE-2023-24824)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pandoc, AlmaLinux:8: pandoc-common&lt;/p&gt;
&lt;p&gt;Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. It can read several dialects of Markdown and (subsets of) HTML, reStructuredText, LaTeX, DocBook, JATS, MediaWiki markup, TWiki markup, TikiWiki markup, Creole 1.0, Haddock markup, OPML, Emacs Org-Mode, Emacs Muse, txt2tags, Vimwiki, Word Docx, ODT, and Textile, and it can write Markdown, reStructuredText, XHTML, HTML 5, LaTeX, ConTeXt, DocBook, JATS, OPML, TEI, OpenDocument, ODT, Word docx, RTF, MediaWiki, DokuWiki, ZimWiki, Textile, groff man, groff ms, plain text, Emacs Org-Mode, AsciiDoc, Haddock markup, EPUB (v2 and v3), FictionBook2, InDesign ICML, Muse, LaTeX beamer slides, PowerPoint, and several kinds of HTML/JavaScript slide shows (S5, Slidy, Slideous, DZSlides, reveal.js). In contrast to most existing tools for converting Markdown to HTML, pandoc has a modular design: it consists of a set of readers, which parse text in a given format and produce a native representation of the document, and a set of writers, which convert this native representation into a target format. Thus, adding an input or output format requires only adding a reader or writer. For pdf output please also install pandoc-pdf.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cmark-gfm: Quadratic complexity bugs may lead to a denial of service (CVE-2023-24824)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:8427</guid>
    </item>
    <item>
      <title>EUVD-2026-214711</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-214711</link>
      <description>EUVD-2026-214711</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-214711</guid>
    </item>
    <item>
      <title>fkie_cve-2023-24824</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-24824</link>
      <description>&lt;p&gt;cmark-gfm is GitHub&amp;#39;s fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing text which leads with either large numbers of `&amp;gt;` or `-` characters. This issue has been addressed in version 0.29.0.gfm.10. Users are advised to upgrade. Users unable to upgrade should validate that their input comes from trusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cmark-gfm is GitHub&amp;#39;s fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing text which leads with either large numbers of `&amp;gt;` or `-` characters. This issue has been addressed in version 0.29.0.gfm.10. Users are advised to upgrade. Users unable to upgrade should validate that their input comes from trusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-24824</guid>
    </item>
    <item>
      <title>gsd-2023-24824</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-24824</link>
      <description>gsd-2023-24824</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-24824</guid>
    </item>
    <item>
      <title>HSEC-2025-0007 — cmark-gfm: resource exhaustion due to quadratic complexity in parser</title>
      <link>https://cve.radiocsirt.org/vuln/hsec-2025-0007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: cmark-gfm&lt;/p&gt;
&lt;p&gt;# cmark-gfm: resource exhaustion due to quadratic complexity in parser&lt;/p&gt;
&lt;p&gt;*cmark-gfm* is GitHub&amp;#39;s fork of *cmark*, a CommonMark parsing and
rendering library and program in C.  A polynomial time complexity
issue in cmark-gfm may lead to unbounded resource exhaustion and
subsequent denial of service, due to quadratic complexity issues
when parsing text which leads with either large numbers of `&amp;gt;` or
`-` characters.&lt;/p&gt;
&lt;p&gt;The Haskell *cmark-gfm* package bundles the C sources and was
affected by this issue.  This fix was released in the upstream C
package at version `0.29.0.gfm.10`.  Version `0.2.6` of the Haskell
package adopted the fix (moving from `0.29.0.gfm.6` to
`0.29.0.gfm.13`).  Packages that depend on *cmark-gfm* should update
to `0.2.6` or later.&lt;/p&gt;
&lt;p&gt;Users unable to update should avoid processing data from untrusted
sources or validate the input with other tools before using
*cmark-gfm* to parse it.&lt;/p&gt;
&lt;p&gt;Pandoc `&amp;lt; 2.10.1` depended on *cmark-gfm* and could be affected by
this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Hackage: cmark-gfm&lt;/p&gt;
&lt;p&gt;# cmark-gfm: resource exhaustion due to quadratic complexity in parser&lt;/p&gt;
&lt;p&gt;*cmark-gfm* is GitHub&amp;#39;s fork of *cmark*, a CommonMark parsing and
rendering library and program in C.  A polynomial time complexity
issue in cmark-gfm may lead to unbounded resource exhaustion and
subsequent denial of service, due to quadratic complexity issues
when parsing text which leads with either large numbers of `&amp;gt;` or
`-` characters.&lt;/p&gt;
&lt;p&gt;The Haskell *cmark-gfm* package bundles the C sources and was
affected by this issue.  This fix was released in the upstream C
package at version `0.29.0.gfm.10`.  Version `0.2.6` of the Haskell
package adopted the fix (moving from `0.29.0.gfm.6` to
`0.29.0.gfm.13`).  Packages that depend on *cmark-gfm* should update
to `0.2.6` or later.&lt;/p&gt;
&lt;p&gt;Users unable to update should avoid processing data from untrusted
sources or validate the input with other tools before using
*cmark-gfm* to parse it.&lt;/p&gt;
&lt;p&gt;Pandoc `&amp;lt; 2.10.1` depended on *cmark-gfm* and could be affected by
this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/hsec-2025-0007</guid>
    </item>
    <item>
      <title>RHSA-2025:8427 — Red Hat Security Advisory: pandoc security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:8427</link>
      <description>&lt;p&gt;cmark-gfm: Quadratic complexity bugs may lead to a denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cmark-gfm: Quadratic complexity bugs may lead to a denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:8427</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-24824</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-24824</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: cmark, Ubuntu:20.04:LTS: cmark, Ubuntu:22.04:LTS: cmark, Ubuntu:24.04:LTS: cmark, Ubuntu:25.10: cmark, Ubuntu:26.04:LTS: cmark&lt;/p&gt;
&lt;p&gt;cmark-gfm is GitHub&amp;#39;s fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing text which leads with either large numbers of `&amp;gt;` or `-` characters. This issue has been addressed in version 0.29.0.gfm.10. Users are advised to upgrade. Users unable to upgrade should validate that their input comes from trusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: cmark, Ubuntu:20.04:LTS: cmark, Ubuntu:22.04:LTS: cmark, Ubuntu:24.04:LTS: cmark, Ubuntu:25.10: cmark, Ubuntu:26.04:LTS: cmark&lt;/p&gt;
&lt;p&gt;cmark-gfm is GitHub&amp;#39;s fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing text which leads with either large numbers of `&amp;gt;` or `-` characters. This issue has been addressed in version 0.29.0.gfm.10. Users are advised to upgrade. Users unable to upgrade should validate that their input comes from trusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-24824</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1213 — Red Hat Enterprise Linux (cmark-gfm): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1213</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1213</guid>
    </item>
  </channel>
</rss>
