Search CVE reports


Toggle filters

1 – 10 of 11 results


CVE-2026-86435

Medium priority
Needs evaluation

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86434

Medium priority
Needs evaluation

league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86433

Medium priority
Needs evaluation

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86432

Medium priority
Needs evaluation

commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86431

Medium priority
Needs evaluation

league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86430

Medium priority
Needs evaluation

league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86429

Medium priority
Needs evaluation

The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-86428

Medium priority
Needs evaluation

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33347

Medium priority

Some fixes available 3 of 5

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Vulnerable Fixed Fixed Fixed
Show less packages

CVE-2026-30838

Medium priority

Some fixes available 3 of 5

league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and...

1 affected package

php-league-commonmark

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
php-league-commonmark Vulnerable Fixed Fixed Fixed
Show less packages