Impact
This vulnerability allows an attacker to trigger a denial‑of‑service condition by exploiting super‑linear work performed by the CommonMark parser. Crafted Markdown inputs containing long back‑tick runs, deeply nested brackets, or excessive emphasis delimiters cause the parser to consume disproportionately high CPU time, delaying or blocking legitimate requests. The weakness is a form of improper resource handling (CWE‑407).
Affected Systems
The affected software is thephpleague CommonMark library, versions prior to 2.9.1. Applications that depend on this library for Markdown rendering, such as content management systems or API endpoints, will be impacted if they use an unpatched version.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability with a significant impact on availability. While an EPSS score is not available, the lack of a KEV listing does not diminish the potential for exploitation, especially in high‑traffic web services where attacker‑constructed Markdown could be submitted easily. The likely attack vector is remote input submitted to any endpoint that invokes the Markdown parser, requiring only that the application accepts user‑supplied Markdown.
OpenCVE Enrichment