CVE-2026-105830
league/commonmark 2.0.0 before 2.10.2 Quadratic DoS via TableStartParser
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() block-start scan. Unauthenticated attackers can submit a large paragraph of pipe-free lines not starting with letters, forcing repeated full-buffer strpos scans that exhaust PHP worker CPU.
| CWE | CWE-400 |
| Vendor | thephpleague |
| Product | commonmark |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for thephpleague commonmark
Be the first to know when new high vulnerabilities affecting thephpleague commonmark are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
thephpleague / commonmark
2.0.0 < 2.10.2
References
Credits
๐ manus-pi ๐ manus-use