CVE-2026-86435

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 13:20

Updated : 2026-09-09 15:17


NVD link : CVE-2026-86435

Mitre link : CVE-2026-86435

CVE.ORG link : CVE-2026-86435


JSON object : View

Products Affected

No product.

CWE
CWE-407

Inefficient Algorithmic Complexity