← Terug naar overzicht

commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension. The vulnerability arises from a failure to deduplicate footnote definitions, allowing attackers to craft malicious documents with duplicate footnote definitions and references. This causes quadratic output expansion, leading to excessive memory and CPU consumption. The attack can exhaust server resources, effectively causing a denial of service. The vulnerability affects the PHP League's commonmark library and has been assigned CVE-2026-86435. A fix is available in version 2.8.4 and later. Users are advised to upgrade to the patched version to mitigate the risk.

Affected products

  • commonmark 1.5.0 - 2.8.3

Related CVE's

  • CVE-2026-86435

Categories

  • Supply Chain & Dependencies
  • Web Technologies