CVE-2026-86432

commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 13:20

Updated : 2026-09-10 16:18


NVD link : CVE-2026-86432

Mitre link : CVE-2026-86432

CVE.ORG link : CVE-2026-86432


JSON object : View

Products Affected

No product.

CWE
CWE-405

Asymmetric Resource Consumption (Amplification)