Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-86429— commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes

Quick assessment

Affected
thephpleague commonmark
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

(thephpleague/commonmark)库在版本 >= 1.5.0 且 < 2.9.1 中,其 和 扩展存在二次解析复杂度问题。当这些扩展被显式注册到 时(它们默认未启用,并且不包含在标准 CommonMark 或 GitHub 风格 Markdown 转换器中),未认证的攻击者可以提交小型、精心构造的 Markdown 文档——例如:文本中交替出现未配对的引号、连续运行的块级属性块,或重复的类属性——从而触发不成比例的 CPU 消耗,导致服务拒绝(DoS)。该问题已在 2.9.1 版本中修复。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1020.001 · Traffic Duplication

Affected Version Matrix 2

VendorProduct Version RangeStatus
thephpleague commonmark 1.5.0< 2.9.1 affected
2.9.1 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86429

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes
Source: CVE Program / CVE List V5
Vulnerability Description
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Fixed in 2.9.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
算法复杂性
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
thephpleague commonmark 1.5.0 ~ 2.9.1 -

II. Public POCs for CVE-2026-86429

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86429

登录查看更多情报信息。

Vendor Advisories for CVE-2026-86429 (2)

Same Patch Batch · thephpleague · 2026-09-07 · 8 CVEs total

CVE-2026-86430 7.5 HIGH league/commonmark before 2.9.1 Denial of Service via parsing
CVE-2026-86435 7.5 HIGH commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote
CVE-2026-86434 7.5 HIGH commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision
CVE-2026-86433 7.5 HIGH commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes
CVE-2026-86428 7.5 HIGH commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes
CVE-2026-86431 7.2 HIGH commonmark before 2.9.1 XSS via AttributesExtension form feed bypass
CVE-2026-86432 5.3 MEDIUM commonmark 2.0.0 before 2.8.4 Denial of Service via XML

IV. Related Vulnerabilities

V. Comments for CVE-2026-86429

No comments yet


Leave a comment