CVE-2026-71488: league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic ti
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-71488
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-71488 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for league/commonmark is a
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-71478: league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 u…nvd · 2026-08-06
- mediumGHSA-mj63-m3rc-8ppr: league/commonmark: Denial of service via deeply nested XML outputghsa · 2026-08-06
- highGHSA-mh25-x5hq-wrqp: league/commonmark: Denial of service via colliding heading slugsghsa · 2026-08-06
- highGHSA-jfm3-95jq-q3rf: league/commonmark: Denial of service via duplicate footnote definitionsghsa · 2026-08-06
- highGHSA-g2gp-3wwq-f4ph: league/commonmark: Denial of service via adjacent inline attribute blocksghsa · 2026-08-06
- highGHSA-2q4p-g7hv-5rgv: league/commonmark: Quadratic-time denial of service when parsing crafted Markdownghsa · 2026-08-06
More from NVD Recent CVEs
- highCVE-2026-19190: A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part …2026-08-07
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…2026-08-07
- unknownCVE-2026-45198: Kernel software from a non-secure operating system on a platform with Trusted Execution Enviro…2026-08-07
- highCVE-2026-19189: A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue …2026-08-07