Impact
The league/commonmark library used in PHP projects is vulnerable to a denial of service when the SmartPunctExtension or AttributesExtension are registered. These extensions introduce quadratic parsing complexity for specially crafted Markdown input, causing disproportionate CPU usage and service interruption. An unauthenticated attacker can submit small documents with alternating quotes, long attribute blocks, or repeated class attributes to trigger the denial of service. The flaw is classified as CWE-407.
Affected Systems
Any deployment of thephpleague/commonmark version 1.5.0 through 2.9.0 that registers the SmartPunctExtension or AttributesExtension. The extensions are not enabled by default, but can be explicitly added to an Environment in the Standard CommonMark or GitHub‑Flavored Markdown converters, exposing applications that process Markdown input to this denial‑of‑service condition.
Risk and Exploitability
The CVSS score of 8.7 reflects a high‑severity denial of service with no authentication requirement. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of authentication and the ability to trigger the issue with minimal input make exploitation likely in exposed web or API services that use commonmark. An attacker can send the crafted Markdown payload over the network, consume CPU resources, and cause application outages, potentially cascading to higher‑level services if the parser is part of a critical workflow.
OpenCVE Enrichment