CVE-2026-86428: Thephpleague Commonmark

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.

Affected products

  • Thephpleague Commonmark: from 1.5.0, before 2.10.0 (fixed in 2.10.0)

Published 2026-09-07. Last modified 2026-10-08.