{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/commonmark--2.0.0--2.8.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:league:commonmark:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-86434"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["commonmark (\u003e= 2.0.0, \u003c 2.8.4)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["league"],"content_html":"\u003cp\u003eThe league/commonmark library, versions 2.0.0 through 2.8.3, contains a denial of service (DoS) vulnerability in the UniqueSlugNormalizer::normalize() function. The issue arises when an application enables specific extensions, namely HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension. The vulnerability occurs because the normalization logic resets its numeric-suffix search from 1 every time a slug collision is detected, leading to O(K^2) time complexity relative to the number of headings (K) that resolve to the same base slug. An unauthenticated attacker can supply a small, crafted Markdown document containing a high volume of headings that collapse into a single base slug (such as empty ATX headings or punctuation-only strings). This consumes excessive CPU resources on the server during the parsing phase, resulting in service unavailability. The vulnerability is addressed in version 2.9.0.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated remote attacker to cause a denial of service on any application utilizing a vulnerable version of the library with the specified extensions enabled. By forcing significant CPU usage, attackers can degrade or completely halt web application services that process user-supplied Markdown content, impacting sites ranging from documentation platforms to content management systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade league/commonmark to version 2.9.0 or later immediately to resolve CVE-2026-86434.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing the library to identify those that have HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension enabled.\u003c/li\u003e\n\u003cli\u003eImplement input validation or size limits on user-supplied Markdown content to mitigate the potential for high-volume heading attacks if immediate patching is not feasible.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-07T15:33:23Z","date_published":"2026-09-07T15:33:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-league-commonmark-dos/","summary":"The league/commonmark library is susceptible to a denial of service attack via crafted Markdown input that triggers quadratic CPU complexity in slug normalization.","title":"Denial of Service Vulnerability in league/commonmark","url":"https://feed.craftedsignal.io/briefs/2026-09-league-commonmark-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Commonmark (\u003e= 2.0.0, \u003c 2.8.4)","version":"https://jsonfeed.org/version/1.1"}