CVE-2026-105830
- EPSS -
- Veröffentlicht 08.10.2026 14:10:31
- Zuletzt bearbeitet 08.10.2026 17:17:12
league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() block-start scan. Unauthenticated attackers can submit a large paragra...
CVE-2026-105829
- EPSS -
- Veröffentlicht 08.10.2026 14:10:30
- Zuletzt bearbeitet 08.10.2026 16:17:01
League CommonMark from 1.3.0 before 2.10.2 contains a cross-site scripting vulnerability that allows users posting Markdown to bypass the DisallowedRawHtml extension by ending raw HTML with a bare disallowed tag name. Attackers can place a lone <scri...
CVE-2024-58382
- EPSS 0.28%
- Veröffentlicht 09.09.2026 13:31:56
- Zuletzt bearbeitet 08.10.2026 16:16:49
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case perf...
CVE-2026-86435
- EPSS 0.28%
- Veröffentlicht 07.09.2026 12:53:53
- Zuletzt bearbeitet 08.10.2026 16:17:58
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create...
CVE-2026-86434
- EPSS 0.29%
- Veröffentlicht 07.09.2026 12:53:53
- Zuletzt bearbeitet 08.10.2026 16:17:57
league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time compl...
CVE-2026-86433
- EPSS 0.29%
- Veröffentlicht 07.09.2026 12:53:52
- Zuletzt bearbeitet 08.10.2026 16:17:57
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated attackers can submit a...
CVE-2026-86432
- EPSS 0.25%
- Veröffentlicht 07.09.2026 12:53:51
- Zuletzt bearbeitet 08.10.2026 16:17:57
commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory...
CVE-2026-86431
- EPSS 0.23%
- Veröffentlicht 07.09.2026 12:53:51
- Zuletzt bearbeitet 08.10.2026 16:17:57
league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g. {\x0Conclick="alert(1)"}) bypasse...
CVE-2026-86430
- EPSS 0.29%
- Veröffentlicht 07.09.2026 12:53:50
- Zuletzt bearbeitet 08.10.2026 16:17:57
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can s...
CVE-2026-86429
- EPSS 0.29%
- Veröffentlicht 07.09.2026 12:53:49
- Zuletzt bearbeitet 08.10.2026 16:17:57
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they...