CVE-2026-86428

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-07 13:20

Updated : 2026-09-09 16:31


NVD link : CVE-2026-86428

Mitre link : CVE-2026-86428

CVE.ORG link : CVE-2026-86428


JSON object : View

Products Affected

thephpleague

  • commonmark
CWE
CWE-407

Inefficient Algorithmic Complexity