league/commonmark Security Advisories for 2.8.3 (6)
-
[MEDIUM] league/commonmark: Denial of service via deeply nested XML output
PKSA-5mzr-szzf-z6cn GHSA-mj63-m3rc-8ppr
Affected version: >=2.0.0,<2.9.0
Reported by:
GitHub -
[HIGH] league/commonmark: Denial of service via colliding heading slugs
PKSA-cqd6-fg4n-nxpf GHSA-mh25-x5hq-wrqp
Affected version: >=2.0.0,<2.9.0
Reported by:
GitHub -
[HIGH] league/commonmark: Denial of service via duplicate footnote definitions
PKSA-1q6p-sqkj-8mmj GHSA-jfm3-95jq-q3rf
Affected version: >=1.5.0,<2.9.0
Reported by:
GitHub -
[HIGH] league/commonmark: Denial of service via adjacent inline attribute blocks
PKSA-mc58-w91n-f5gv GHSA-g2gp-3wwq-f4ph
Affected version: >=1.5.0,<2.9.0
Reported by:
GitHub -
[HIGH] league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
PKSA-t21r-vtr5-3mdz CVE-2026-71488 GHSA-2q4p-g7hv-5rgv
Affected version: >=0.6.0,<2.9.0
Reported by:
GitHub -
[MEDIUM] league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
PKSA-scnn-p8mm-jbft CVE-2026-71478 GHSA-29pj-957v-52mc
Affected version: >=1.5.0,<=2.8.3
Reported by:
GitHub