Description
league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service.
Published: 2026-09-07
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the UniqueSlugNormalizer::normalize() method of thephpleague/commonmark. During normalization, the method restarts its numeric‑suffix enumeration from 1 each time a slug collision occurs, causing quadratic time complexity relative to the number of headings that share the same base slug. The flaw can be triggered by any of the HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension when they are registered. An unauthenticated attacker can craft a Markdown document containing many headings that resolve to the same slug—such as empty or identical ATX headings, or headings made only of punctuation—to force the library to perform excessive CPU work, leading to a denial of service.

Affected Systems

thephpleague:commonmark v2.0.0 through v2.8.3 (any release before 2.9.0) is affected. The issue was resolved in CommonMark version 2.9.0.

Risk and Exploitability

The CVSS score of 8.7 marks this flaw as high severity. With no EPSS data available the exploitation likelihood is uncertain, but the absence of a KEV listing suggests no currently documented exploitation. Attackers can trigger the denial of service by submitting a malicious Markdown document to any application that loads the vulnerable CommonMark library, regardless of authentication, and the CPU‑intensive slug collision routine will consume resources until the process stalls. Because the flaw does not require elevated privileges, the impact is limited to availability, but the high impact score indicates that a successful attack can disrupt services that depend on the library.

Generated by OpenCVE AI on September 7, 2026 at 15:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to CommonMark 2.9.0 or later, which includes the algorithm fix.
  • If an upgrade cannot be performed immediately, disable the HeadingPermalinkExtension, FootnoteExtension, and TableOfContentsExtension until the library is patched.
  • Add input validation to limit the number of headings that resolve to the same slug or reject documents containing large numbers of heading collisions to reduce the risk of excessive CPU usage.

Generated by OpenCVE AI on September 7, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service.
Title commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision
First Time appeared Thephpleague
Thephpleague commonmark
Weaknesses CWE-407
CPEs cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*
Vendors & Products Thephpleague
Thephpleague commonmark
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Thephpleague Commonmark
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T14:21:56.985Z

Reserved: 2026-09-07T12:34:31.457Z

Link: CVE-2026-86434

cve-icon Vulnrichment

Updated: 2026-09-19T14:20:23.866Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T13:20:42.870

Modified: 2026-09-19T15:17:06.503

Link: CVE-2026-86434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:45:17Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity