Description
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing.
Published: 2026-09-07
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker to trigger a denial‑of‑service condition by exploiting super‑linear work performed by the CommonMark parser. Crafted Markdown inputs containing long back‑tick runs, deeply nested brackets, or excessive emphasis delimiters cause the parser to consume disproportionately high CPU time, delaying or blocking legitimate requests. The weakness is a form of improper resource handling (CWE‑407).

Affected Systems

The affected software is thephpleague CommonMark library, versions prior to 2.9.1. Applications that depend on this library for Markdown rendering, such as content management systems or API endpoints, will be impacted if they use an unpatched version.

Risk and Exploitability

The CVSS score of 8.7 classifies this as a high‑severity vulnerability with a significant impact on availability. While an EPSS score is not available, the lack of a KEV listing does not diminish the potential for exploitation, especially in high‑traffic web services where attacker‑constructed Markdown could be submitted easily. The likely attack vector is remote input submitted to any endpoint that invokes the Markdown parser, requiring only that the application accepts user‑supplied Markdown.

Generated by OpenCVE AI on September 7, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to version 2.9.1 or later of thephpleague CommonMark.
  • Implement rate limiting or input size restrictions on requests that contain Markdown content to reduce CPU consumption.
  • Validate or sanitize Markdown input to remove excessive back‑tick runs, deeply nested brackets, or long emphasis delimiters before passing it to the parser.

Generated by OpenCVE AI on September 7, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing.
Title league/commonmark before 2.9.1 Denial of Service via parsing
First Time appeared Thephpleague
Thephpleague commonmark
Weaknesses CWE-407
CPEs cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Vendors & Products Thephpleague
Thephpleague commonmark
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Thephpleague Commonmark
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:31:20.523Z

Reserved: 2026-09-07T12:34:31.457Z

Link: CVE-2026-86430

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T13:20:42.320

Modified: 2026-09-10T19:19:38.113

Link: CVE-2026-86430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:15:17Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity