commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources. | |
| Title | commonmark 2.0.0 before 2.8.4 Denial of Service via XML | |
| First Time appeared |
Thephpleague
Thephpleague commonmark |
|
| Weaknesses | CWE-405 | |
| CPEs | cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thephpleague
Thephpleague commonmark |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-07T12:53:51.897Z
Reserved: 2026-09-07T12:34:31.457Z
Link: CVE-2026-86432
No data.
Status : Received
Published: 2026-09-07T13:20:42.600
Modified: 2026-09-07T13:20:42.600
Link: CVE-2026-86432
No data.
OpenCVE Enrichment
No data.
Weaknesses