league/commonmark Security Advisories for 2.3.2 (10)
-
[MEDIUM] league/commonmark: Denial of service via deeply nested XML output
PKSA-5mzr-szzf-z6cn GHSA-mj63-m3rc-8ppr
Affected version: >=2.0.0,<2.9.0
Reported by:
GitHub -
[HIGH] league/commonmark: Denial of service via colliding heading slugs
PKSA-cqd6-fg4n-nxpf GHSA-mh25-x5hq-wrqp
Affected version: >=2.0.0,<2.9.0
Reported by:
GitHub -
[HIGH] league/commonmark: Denial of service via duplicate footnote definitions
PKSA-1q6p-sqkj-8mmj GHSA-jfm3-95jq-q3rf
Affected version: >=1.5.0,<2.9.0
Reported by:
GitHub -
[HIGH] league/commonmark: Denial of service via adjacent inline attribute blocks
PKSA-mc58-w91n-f5gv GHSA-g2gp-3wwq-f4ph
Affected version: >=1.5.0,<2.9.0
Reported by:
GitHub -
[HIGH] league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
PKSA-t21r-vtr5-3mdz CVE-2026-71488 GHSA-2q4p-g7hv-5rgv
Affected version: >=0.6.0,<2.9.0
Reported by:
GitHub -
[MEDIUM] league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
PKSA-scnn-p8mm-jbft CVE-2026-71478 GHSA-29pj-957v-52mc
Affected version: >=1.5.0,<=2.8.3
Reported by:
GitHub -
[MEDIUM] league/commonmark has an embed extension allowed_domains bypass
PKSA-21fb-n1x5-5nf7 CVE-2026-33347 GHSA-hh8v-hgvp-g3f5
Affected version: >=2.3.0,<=2.8.1
Reported by:
GitHub -
[MEDIUM] CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names
PKSA-2cx9-ynrq-qdk3 CVE-2026-30838 GHSA-4v6x-c7xx-hw9f
Affected version: >=2.0.0,<=2.8.0
Reported by:
GitHub -
[MEDIUM] league/commonmark contains a XSS vulnerability in Attributes extension
PKSA-rqc2-tcc6-nc79 CVE-2025-46734 GHSA-3527-qv2q-pfvx
Affected version: >=1.5.0,<2.7.0
Reported by:
GitHub -
[HIGH] league/commonmark's quadratic complexity bugs may lead to a denial of service
PKSA-fndg-qryc-dyc9 GHSA-c2pc-g5qf-rfrf
Affected version: <2.6.0
Reported by:
GitHub