Denial of Service Vulnerabilities in CommonMark Library

Denial of Service Vulnerabilities in CommonMark Library

First seen 8 Sep 2026, 05:32 UTC Redpacketsecurity 60.6

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities (CVE-2026-86429 and CVE-2026-86428) were disclosed in the thephpleague/commonmark library, affecting versions 1.5.0 to 2.9.1 and 1.5.0 to before 2.10.0, respectively. Both vulnerabilities allow unauthenticated attackers to exploit quadratic parsing complexity in Markdown processing, leading to denial of service through excessive CPU consumption. The vulnerabilities are particularly concerning for internet-facing PHP applications that handle user-generated content, such as forums and documentation platforms. CVE-2026-86429 involves the SmartPunctExtension and AttributesExtension, while CVE-2026-86428 focuses on distinctly-named attributes. Both vulnerabilities were published on 2026-09-07 and require urgent remediation, although no active exploitation or proof-of-concept code has been confirmed yet. Affected systems should upgrade to version 2.9.1 or later for CVE-2026-86429 and to version 2.10.0 or later for CVE-2026-86428 to mitigate the risks.

Key Points: • CVE-2026-86429 and CVE-2026-86428 allow denial of service via CPU exhaustion. • Both vulnerabilities affect the thephpleague/commonmark library versions 1.5.0 to 2.9.1 and 1.5.0 to before 2.10.0. • Immediate upgrades to patched versions are necessary to mitigate risks.

Ask AI about this cluster

Timeline

2026-09-07
CVE-2026-86429 published
CVE-2026-86429 disclosed, affecting thephpleague/commonmark versions 1.5.0 to 2.9.1, allowing denial of service through CPU exhaustion.
Redpacketsecurity
2026-09-07
CVE-2026-86428 published
CVE-2026-86428 disclosed, affecting thephpleague/commonmark versions 1.5.0 to before 2.10.0, also allowing denial of service via CPU exhaustion.
Redpacketsecurity