Impact
league/commonmark from version 2.0.0 up to but not including 2.10.2 contains a quadratic‑time denial‑of‑service flaw in the TableStartParser::tryStart() routine. Unauthenticated users can submit a paragraph composed of pipe‑free lines that do not begin with letters, forcing the parser to repeatedly scan the entire buffer with strpos and rapidly consume CPU resources. The weakness is a classic resource exhaustion problem identified as CWE‑400.
Affected Systems
The affected product is thephpleague commonmark. Any installation of the library in the version range 2.0.0 through 2.10.1 is vulnerable; version 2.10.2 and later contain the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating a high severity. EPSS is not available and the flaw is not listed in the CISA KEV catalog. Attackers need no authentication and can exploit the issue by feeding large amounts of specially crafted markdown content to any service that uses commonmark. Because the flaw is purely computational, it can be triggered remotely and will cause a denial of service by exhausting PHP worker CPU.
OpenCVE Enrichment