commonmark 从 1.5.0 起至 2.10.0 之前的版本中, 在处理具有不同名称的属性时存在服务拒绝(DoS)漏洞。攻击者可以提交包含大量不同属性名称的 Markdown 内容,从而导致属性合并与过滤操作出现二次方级时间复杂度,消耗不成比例的 CPU 资源,进而导致正常请求无法完成处理。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| thephpleague | commonmark | 1.5.0< 2.10.0 |
affected |
2.10.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| thephpleague | commonmark | 1.5.0 ~ 2.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86430 | 7.5 HIGH | league/commonmark before 2.9.1 Denial of Service via parsing |
| CVE-2026-86429 | 7.5 HIGH | commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes |
| CVE-2026-86435 | 7.5 HIGH | commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote |
| CVE-2026-86434 | 7.5 HIGH | commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision |
| CVE-2026-86433 | 7.5 HIGH | commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes |
| CVE-2026-86431 | 7.2 HIGH | commonmark before 2.9.1 XSS via AttributesExtension form feed bypass |
| CVE-2026-86432 | 5.3 MEDIUM | commonmark 2.0.0 before 2.8.4 Denial of Service via XML |
No comments yet