Description
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Fixed in 2.9.1.
Published: 2026-09-07
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The league/commonmark library used in PHP projects is vulnerable to a denial of service when the SmartPunctExtension or AttributesExtension are registered. These extensions introduce quadratic parsing complexity for specially crafted Markdown input, causing disproportionate CPU usage and service interruption. An unauthenticated attacker can submit small documents with alternating quotes, long attribute blocks, or repeated class attributes to trigger the denial of service. The flaw is classified as CWE-407.

Affected Systems

Any deployment of thephpleague/commonmark version 1.5.0 through 2.9.0 that registers the SmartPunctExtension or AttributesExtension. The extensions are not enabled by default, but can be explicitly added to an Environment in the Standard CommonMark or GitHub‑Flavored Markdown converters, exposing applications that process Markdown input to this denial‑of‑service condition.

Risk and Exploitability

The CVSS score of 8.7 reflects a high‑severity denial of service with no authentication requirement. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of authentication and the ability to trigger the issue with minimal input make exploitation likely in exposed web or API services that use commonmark. An attacker can send the crafted Markdown payload over the network, consume CPU resources, and cause application outages, potentially cascading to higher‑level services if the parser is part of a critical workflow.

Generated by OpenCVE AI on September 7, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade thephpleague/commonmark to version 2.9.1 or later.
  • If upgrading is not immediately possible, avoid registering the SmartPunctExtension or AttributesExtension when processing untrusted Markdown input.
  • As a temporary measure, limit the size of Markdown documents processed or impose timeouts on parsing to mitigate CPU exhaustion.
  • Consider isolating the Markdown parser in a separate container or sandbox with resource limits to protect other services if a denial of service occurs.

Generated by OpenCVE AI on September 7, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Fixed in 2.9.1.
Title commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes
First Time appeared Thephpleague
Thephpleague commonmark
Weaknesses CWE-407
CPEs cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Vendors & Products Thephpleague
Thephpleague commonmark
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Thephpleague Commonmark
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T14:21:57.146Z

Reserved: 2026-09-07T12:33:13.368Z

Link: CVE-2026-86429

cve-icon Vulnrichment

Updated: 2026-09-19T14:20:35.972Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T13:20:42.180

Modified: 2026-09-19T15:17:06.363

Link: CVE-2026-86429

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T16:30:06Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity