commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources. | |
| Title | commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote | |
| First Time appeared |
Thephpleague
Thephpleague commonmark |
|
| Weaknesses | CWE-407 | |
| CPEs | cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thephpleague
Thephpleague commonmark |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-07T12:53:53.897Z
Updated: 2026-09-09T14:32:07.292Z
Reserved: 2026-09-07T12:34:31.457Z
Link: CVE-2026-86435
Updated: 2026-09-09T14:31:57.195Z
Status : Awaiting Analysis
Published: 2026-09-07T13:20:43.013
Modified: 2026-09-09T15:17:18.217
Link: CVE-2026-86435
No data.