CVE-2026-86430

NameCVE-2026-86430
Descriptionleague/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-league-commonmark (PTS)bookworm2.3.9-1+deb12u1vulnerable
trixie2.7.0-1+deb13u1vulnerable
forky, sid2.10.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-league-commonmarksource(unstable)2.10.0-1

Notes

https://github.com/thephpleague/commonmark/security/advisories/GHSA-j8pm-gj4c-rq4x
Fixed by: https://github.com/thephpleague/commonmark/commit/d9375fadc308a63a02950a68d822417a6e4c33b2 (2.9.1)
Fixed by: https://github.com/thephpleague/commonmark/commit/0768217751fbfaeb8d76762f6944e9af7114295e (2.9.1)
Fixed by: https://github.com/thephpleague/commonmark/commit/e0036ef031fd36ec1c3c82db8743fc928b5271c8 (2.9.1)

Search for package or bug name: Reporting problems