Skip to content
CVE Alert: CVE-2026-86435 – thephpleague

CVE Alert: CVE-2026-86435 – thephpleague

Redpacketsecurity •admin • September 8, 2026

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources.

## AI Summary Analysis

**Risk verdict:** High availability risk for internet-facing applications, but KEV, SSVC exploitation status, EPSS and PoC indicators are not supplied, so exploitation urgency cannot be confirmed.

**Why this matters:** A remote unauthenticated attacker may be able to consume excessive application CPU and memory, causing degraded performance or service outage. The primary business impact is loss of availability for websites, APIs, documentation platforms, content pipelines or other services that parse untrusted Markdown; confidentiality and integrity impact appear limited.

**Most likely attack path:** The attack is network-reachable (AV:N), requires low effort (AC:L), has no stated attack requirements (AT:N), needs no privileges (PR:N), and requires no user interaction (UI:N). Scope is unchanged, so direct impact should remain within the vulnerable service, although shared hosts, autoscaling capacity and dependent services could suffer cascading availability effects.

**Who is most exposed:** Public-facing PHP applications that render user-submitted, imported or externally sourced Markdown with the Footnote extension enabled are the main concern. Multi-tenant platforms and services processing large volumes of content merit particular attention.

Alert on abnormal growth in Markdown request size or footnote count.

Monitor parser latency, PHP worker saturation, memory exhaustion and restart rates.

Correlate repeated requests containing duplicated footnote definitions or references.

Review web, WAF and application logs for unauthenticated submissions preceding resource spikes.

Mitigation and prioritisation:

Upgrade the dependency promptly to the vendor-fixed release; treat as high-priority remediation.

If unavailable, disable Footnote processing or reject excessive and duplicated definitions.

Apply request-size, execution-time, memory and concurrency limits at the edge and application layers.

Test changes against representative content and use staged deployment with rollback capacity.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

Platforms (2)