Back Redpacketsecurity CVE Alert: CVE-2026-86434 – thephpleague
league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service.
## AI Summary Analysis
**Risk verdict:** High availability risk for internet-facing Markdown services, but no KEV, active SSVC exploitation, PoC, or EPSS assessment is provided to justify emergency exploitation-led prioritisation.
**Why this matters:** An attacker can consume disproportionate CPU with a deliberately small request, potentially exhausting application workers and degrading websites, documentation portals, APIs, or content pipelines. The likely business impact is loss of availability rather than data theft or unauthorised modification; repeated requests could also create infrastructure cost and trigger cascading service failures.
**Most likely attack path:** The vulnerable processing path is network-reachable, requires low effort, no privileges, no user interaction, and has no stated attack-environment dependency. An attacker submits crafted Markdown to an endpoint that renders or processes it with the relevant extension enabled; scope is unchanged, so direct lateral movement is unlikely, although shared worker pools or hosts may affect neighbouring applications.
**Who is most exposed:** Public , knowledge-base, documentation, publishing, and Markdown-to-HTML conversion services are the principal targets, especially where untrusted submissions are rendered synchronously.
Alert on repeated rendering requests with unusually high CPU time or latency.
Correlate request bodies containing many repeated, empty, or punctuation-heavy headings.
Monitor worker saturation, queue growth, timeouts, and forced process restarts.
Profile rendering calls to identify excessive time in slug or heading normalisation.
Mitigation and prioritisation:
Apply the vendor’s fixed release promptly; treat as a high-priority availability patch.
Until deployment, disable affected heading-related extensions or restrict untrusted Markdown rendering.
Enforce request size, heading-count, CPU-time, concurrency, and rate limits.
Test representative documents and schedule rollout with rollback capacity; EPSS and exploitation-status data are still needed for finer prioritisation.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
