<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Commonmark (&gt;= 2.0.0, &lt;= 2.10.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/commonmark--2.0.0--2.10.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:27:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/commonmark--2.0.0--2.10.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Quadratic Time Denial of Service in league/commonmark Table Extension</title><link>https://feed.craftedsignal.io/briefs/2026-09-league-commonmark-dos/</link><pubDate>Wed, 30 Sep 2026 16:27:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-league-commonmark-dos/</guid><description>An unauthenticated remote attacker can cause denial of service by submitting large Markdown paragraphs that trigger O(M^2) CPU consumption in the league/commonmark TableStartParser.</description><content:encoded><![CDATA[<p>The <code>league/commonmark</code> library, specifically in versions 2.0.0 through 2.10.1, contains a quadratic-time complexity vulnerability in its GitHub Flavored Markdown (GFM) Table extension. The <code>TableStartParser</code> performs a full-buffer scan of the accumulated paragraph on every new line via <code>strpos()</code> to check for potential table headers. Because the paragraph buffer grows indefinitely as long as non-blank lines are provided, and the scan traverses this entire buffer repeatedly, the work required grows quadratically (O(M^2)) relative to the input size. An unauthenticated attacker can exploit this by submitting large paragraphs consisting of lines that do not start with a letter (bypassing the <code>SkipLinesStartingWithLettersParser</code>) and contain no pipe characters. This causes excessive CPU usage, which can exhaust available PHP worker processes and result in a denial of service.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li><strong>Exposure:</strong> The attacker identifies an application using <code>league/commonmark</code> (specifically with <code>GithubFlavoredMarkdownConverter</code> or the <code>TableExtension</code> enabled) that processes untrusted Markdown content.</li>
<li><strong>Control:</strong> The attacker prepares a large Markdown body consisting of a single paragraph with no blank lines, no pipe (<code>|</code>) characters, and lines beginning with non-letter characters (e.g., digits).</li>
<li><strong>Path:</strong> As the parser processes the input, the <code>ParagraphParser</code> keeps the paragraph block open, causing the library to append each line to the growing <code>paragraph</code> buffer.</li>
<li><strong>Bypass:</strong> Since the input lines do not begin with a letter, the <code>SkipLinesStartingWithLettersParser</code> returns <code>BlockStart::abort()</code>, allowing the parser to continue searching for other block types.</li>
<li><strong>Primitive:</strong> The <code>MarkdownParser</code> dispatches the input to the <code>TableStartParser::tryStart()</code> on every line, which executes <code>strpos($paragraph, '|')</code> against the entire, continuously growing buffer.</li>
<li><strong>Guard Absence:</strong> No input-size caps or effective length guards prevent the cumulative buffer growth or the exhaustive scan, allowing the O(M^2) complexity to manifest.</li>
<li><strong>Result:</strong> The cumulative processing time leads to extreme CPU load, effectively exhausting server resources and denying service to legitimate users.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a denial of service by consuming all available server resources or PHP worker threads. The impact is limited to availability, with no risk to data confidentiality or integrity. Applications rendering untrusted Markdown from external users are at the highest risk. Measured benchmarks demonstrate that doubling a multi-megabyte input quadruples the CPU time, with 200,000 lines taking approximately 27.81 seconds to parse.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade <code>league/commonmark</code> to a version where this vulnerability is remediated (as of this writing, no fix is available; monitor the upstream repository for updates).</li>
<li>Implement application-level constraints on the total length of user-submitted Markdown content before passing it to the converter.</li>
<li>If not required, disable the <code>TableExtension</code> in the <code>GithubFlavoredMarkdownConverter</code> configuration when processing untrusted input.</li>
<li>Monitor application server CPU usage patterns specifically for PHP-FPM worker saturation coinciding with requests to Markdown rendering endpoints.</li>
</ol>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>