{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/commonmark--2.6.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-58382"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["commonmark (\u003c 2.6.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["thephpleague"],"content_html":"\u003cp\u003eThe PHP library league/commonmark, specifically versions prior to 2.6.0, is susceptible to a denial-of-service (DoS) vulnerability (CVE-2024-58382). The issue stems from polynomial time complexity within the library's Markdown parsing logic. An unauthenticated attacker can submit specifically crafted, malicious Markdown strings that force the parser into a worst-case performance scenario. When these requests are submitted concurrently or at a high frequency, the resulting computational load consumes excessive CPU resources and exhausts available PHP-FPM worker processes, effectively rendering the host application unresponsive to legitimate user traffic. This vulnerability represents a significant risk for any application that accepts user-provided Markdown content without robust input sanitization or resource rate limiting. Defenders should prioritize patching to version 2.6.0 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in service unavailability. By exhausting CPU resources and PHP-FPM processes, an attacker can crash the application or prevent it from processing legitimate requests. This poses a high availability risk to any web platform utilizing commonmark for user-generated content, such as forums, comment sections, or document editors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade league/commonmark to version 2.6.0 or later immediately to address the underlying parser flaw associated with CVE-2024-58382.\u003c/li\u003e\n\u003cli\u003eImplement request rate limiting for endpoints that accept and process user-supplied Markdown to mitigate the risk of concurrent resource exhaustion.\u003c/li\u003e\n\u003cli\u003eMonitor PHP-FPM process pools for unexpected saturation or persistent high CPU utilization, which may indicate active exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T14:58:12Z","date_published":"2026-09-09T14:58:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-58382-dos/","summary":"The league/commonmark package versions prior to 2.6.0 contain a polynomial time complexity vulnerability allowing unauthenticated attackers to cause denial-of-service via crafted Markdown inputs.","title":"Polynomial Time Complexity Denial of Service in league/commonmark","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-58382-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Commonmark (\u003c 2.6.0)","version":"https://jsonfeed.org/version/1.1"}