Impact
The vulnerability resides in the UniqueSlugNormalizer::normalize() method of thephpleague/commonmark. During normalization, the method restarts its numeric‑suffix enumeration from 1 each time a slug collision occurs, causing quadratic time complexity relative to the number of headings that share the same base slug. The flaw can be triggered by any of the HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension when they are registered. An unauthenticated attacker can craft a Markdown document containing many headings that resolve to the same slug—such as empty or identical ATX headings, or headings made only of punctuation—to force the library to perform excessive CPU work, leading to a denial of service.
Affected Systems
thephpleague:commonmark v2.0.0 through v2.8.3 (any release before 2.9.0) is affected. The issue was resolved in CommonMark version 2.9.0.
Risk and Exploitability
The CVSS score of 8.7 marks this flaw as high severity. With no EPSS data available the exploitation likelihood is uncertain, but the absence of a KEV listing suggests no currently documented exploitation. Attackers can trigger the denial of service by submitting a malicious Markdown document to any application that loads the vulnerable CommonMark library, regardless of authentication, and the CPU‑intensive slug collision routine will consume resources until the process stalls. Because the flaw does not require elevated privileges, the impact is limited to availability, but the high impact score indicates that a successful attack can disrupt services that depend on the library.
OpenCVE Enrichment