CommonMark 从 1.5.0 到 2.8.4 之前的版本中,Footnote(脚注)扩展存在一个拒绝服务(DoS)漏洞:脚注定义的重复检查缺失。攻击者可以通过构造包含重复脚注定义和引用的文档,引发二次方(quadratic)输出膨胀,从而消耗过多的内存和 CPU,耗尽服务器资源。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| thephpleague | commonmark | 1.5.0< 2.8.4 |
affected |
2.8.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| thephpleague | commonmark | 1.5.0 ~ 2.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86430 | 7.5 HIGH | league/commonmark before 2.9.1 Denial of Service via parsing |
| CVE-2026-86429 | 7.5 HIGH | commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes |
| CVE-2026-86434 | 7.5 HIGH | commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision |
| CVE-2026-86433 | 7.5 HIGH | commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes |
| CVE-2026-86428 | 7.5 HIGH | commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes |
| CVE-2026-86431 | 7.2 HIGH | commonmark before 2.9.1 XSS via AttributesExtension form feed bypass |
| CVE-2026-86432 | 5.3 MEDIUM | commonmark 2.0.0 before 2.8.4 Denial of Service via XML |
No comments yet