CVE-2026-105830: Thephpleague Commonmark
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() block-start scan. Unauthenticated attackers can submit a large paragraph of pipe-free lines not starting with letters, forcing repeated full-buffer strpos scans that exhaust PHP worker CPU.
Affected products
- Thephpleague Commonmark: from 2.0.0, before 2.10.2 (fixed in 2.10.2)
Published 2026-10-08. Last modified 2026-10-08.