league/commonmark 2.6.0 之前的版本存在多项漏洞,其 Markdown 解析过程中存在多项式时间复杂度的缺陷,攻击者可借此引发拒绝服务(DoS)攻击。攻击者可以提交精心构造的 Markdown 输入,以触发最坏情况下的性能瓶颈;同时,并行发送多个请求会耗尽 CPU 资源和 PHP-FPM 进程,从而导致服务不可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| thephpleague | commonmark | 0 ~ 2.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet