Back Redpacketsecurity CVE Alert: CVE-2026-86433 – thephpleague
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated attackers can submit approximately 32 KB of repeated attribute blocks to cause parsing to take over 5 seconds, exhausting server resources.
**Risk verdict** This is a high-impact availability risk: remotely reachable, unauthenticated exploitation appears straightforward, but KEV, SSVC exploitation status, EPSS and PoC indicators are not supplied, so active exploitation cannot be confirmed.
**Why this matters** A crafted request can consume disproportionate parsing time and tie up worker, CPU or queue capacity. Repeated requests could degrade or interrupt public-facing publishing, API, documentation or content-management services, causing outages without requiring data access or modification. The main uncertainty is the application’s exposure of the vulnerable parsing extension and its resource limits.
**Most likely attack path** With AV:N, AC:L, PR:N and UI:N, an attacker can send specially formed input directly to an exposed endpoint; no account or victim action is needed. Scope is unchanged, so impact is centred on the targeted service rather than direct compromise of connected systems, although downstream availability may suffer if shared infrastructure is saturated.
**Who is most exposed** Internet-facing PHP applications that render untrusted Markdown or user-generated content are the priority, particularly shared hosting, documentation, forum, CMS and API workloads.
Alert on repeated requests containing large or repetitive attribute syntax.
Correlate parser latency, 5xx responses, worker exhaustion and CPU spikes.
Inspect access logs for one source testing multiple content endpoints.
Add application metrics for parse duration and input size.
Mitigation and prioritisation
Upgrade to the fixed release promptly; test representative content and parser extensions first.
Temporarily disable the affected extension where feasible.
Enforce request-size, parse-time, concurrency and rate limits at edge and application tiers.
Isolate parsing workers and monitor capacity.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
