CVE-2026-86435

NameCVE-2026-86435
Descriptioncommonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-league-commonmark (PTS)bookworm2.3.9-1+deb12u1vulnerable
trixie2.7.0-1+deb13u1vulnerable
forky, sid2.10.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-league-commonmarksource(unstable)2.9.0-1

Notes

https://github.com/thephpleague/commonmark/security/advisories/GHSA-jfm3-95jq-q3rf
Fixed by: https://github.com/thephpleague/commonmark/commit/66028124a17ba193da7b11cc3dfda92df21bfbf4 (2.9.0)

Search for package or bug name: Reporting problems