CVE-2024-58382

NameCVE-2024-58382
Descriptionleague/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case performance, and sending multiple requests in parallel exhausts CPU resources and PHP-FPM processes.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-league-commonmark (PTS)bookworm2.3.9-1+deb12u1vulnerable
trixie2.7.0-1+deb13u1fixed
forky, sid2.10.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-league-commonmarksource(unstable)2.6.0-1

Notes

https://github.com/thephpleague/commonmark/security/advisories/GHSA-c2pc-g5qf-rfrf

Search for package or bug name: Reporting problems