Skip to content
CVE Alert: CVE-2026-86430 – thephpleague

CVE Alert: CVE-2026-86430 – thephpleague

Redpacketsecurity •admin • September 8, 2026

league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing.

## AI Summary Analysis

**Risk verdict:** High availability risk for internet-facing Markdown processing, requiring prompt remediation, although no active exploitation status is supplied to justify an emergency designation.

**Why this matters:** An unauthenticated remote requester may be able to consume disproportionate application CPU, causing slow responses, worker exhaustion, queue growth, or service interruption. The likely attacker objective is nuisance disruption or denial of service against APIs, systems, documentation platforms, and content-management workflows rather than data theft or modification. KEV, SSVC, EPSS, and PoC indicators are not present, so exploitation likelihood remains uncertain.

**Most likely attack path:** The attack requires only network access: complexity is low, no special conditions, credentials, or user interaction are expected. A crafted Markdown submission reaches the parser through a public endpoint; scope is unchanged, so the primary impact is exhaustion of the processing service rather than direct compromise of adjacent systems. Risk increases where parsing is synchronous or performed by a limited worker pool.

**Who is most exposed:** Public-facing PHP applications accepting user-generated Markdown, particularly , ticket, forum, wiki, and API services. Multi-tenant platforms and systems lacking request-size or execution-time limits have greater blast-radius potential.

Alert on CPU saturation correlated with Markdown-processing routes.

Track parser latency, worker exhaustion, queue depth, and request timeouts.

Identify unusually long or structurally repetitive Markdown payloads.

Review spikes in anonymous submissions and repeated requests from one source.

Mitigation and prioritisation:

Upgrade the dependency to its fixed release and test representative Markdown content.

Apply strict body-size, parsing-time, rate, and concurrency limits.

Isolate parsing workers and enforce process-level CPU and memory ceilings.

If KEV or EPSS data later confirms active exploitation or a score of 0.5+, treat as priority 1; otherwise schedule as high-priority change with rollback prepared.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)