league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing. | |
| Title | league/commonmark before 2.9.1 Denial of Service via parsing | |
| First Time appeared |
Thephpleague
Thephpleague commonmark |
|
| Weaknesses | CWE-407 | |
| CPEs | cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thephpleague
Thephpleague commonmark |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-07T12:53:50.575Z
Updated: 2026-09-09T14:31:20.523Z
Reserved: 2026-09-07T12:34:31.457Z
Link: CVE-2026-86430
No data.
Status : Undergoing Analysis
Published: 2026-09-07T13:20:42.320
Modified: 2026-09-09T15:17:18.047
Link: CVE-2026-86430
No data.