CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-86429: commonmark from 1.5.0 (inclusive), before 2.9.1 (exclusive), 1.5.0 to before 2.9.1

CVE-2026-86429. CVSS 3.1 base score 7.5 (HIGH, Vendor/CNA). EPSS 0.00515 (percentile 0.41913), scored 2026-10-06.

Affected technology

commonmark · from 1.5.0 (inclusive), before 2.9.1 (exclusive)
thephpleague

commonmark · 1.5.0 to before 2.9.1
thephpleague

Description’s affected range: versions >= 1.5.0 and < 2.9.1

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source says when either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Vendor/CNA’s CVSS 4.0 assessment (base score 8.7/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-407
CCR priority
30.1 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · Vendor/CNA
EPSS
0.00515 · percentile 0.42019 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-86429.html