league/commonmark vulnerabilities
CVEs whose affected-version data names the league/commonmark package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
10 CVEsRSS
GHSA-j8pm-gj4c-rq4xHigh· 7.5league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
GHSA-f8fg-pg57-v4j8High· 7.2league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
GHSA-jjv6-8j6v-6j52High· 7.5league/commonmark: Denial of service in the SmartPunct and Attributes extensions
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
GHSA-8rr7-cvq3-gmfhHigh· 7.5league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
CVE-2026-71478Medium· 6.1league/commonmark is a PHP library for parsing and rendering CommonMark Markdown
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage retur…
CVE-2026-71488High· 7.5league/commonmark is a PHP library for parsing and rendering CommonMark Markdown
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing pa…
GHSA-g2gp-3wwq-f4phHigh· 7.5league/commonmark: Denial of service via adjacent inline attribute blocks
league/commonmark: Denial of service via adjacent inline attribute blocks
GHSA-jfm3-95jq-q3rfHigh· 7.5league/commonmark: Denial of service via duplicate footnote definitions
league/commonmark: Denial of service via duplicate footnote definitions
GHSA-mh25-x5hq-wrqpHigh· 7.5league/commonmark: Denial of service via colliding heading slugs
league/commonmark: Denial of service via colliding heading slugs
GHSA-mj63-m3rc-8pprMedium· 5.3league/commonmark: Denial of service via deeply nested XML output
league/commonmark: Denial of service via deeply nested XML output