CVE-2026-86432: Thephpleague Commonmark
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources.
Affected products
- Thephpleague Commonmark: from 2.0.0, before 2.8.4 (fixed in 2.8.4)
Published 2026-09-07. Last modified 2026-10-08.