commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-07 13:20
Updated : 2026-09-10 16:18
NVD link : CVE-2026-86432
Mitre link : CVE-2026-86432
CVE.ORG link : CVE-2026-86432
JSON object : View
Products Affected
No product.
CWE
CWE-405
Asymmetric Resource Consumption (Amplification)
