Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.0 Laravel GHSA-3q6v-r5mr-hxv8 CVE-2026-105830 PKSA-m4t9-vsgq-8khn

league/commonmark: Quadratic-Time Denial of Service in GFM Table Extension (CVE-2026-105830)

A denial-of-service flaw in league/commonmark's GitHub Flavored Markdown Table extension allows unauthenticated attackers to exhaust CPU resources by submitting crafted Markdown input. Fixed in version 2.10.2.

AI summary

A denial-of-service vulnerability has been identified in league/commonmark, a widely used PHP Markdown parsing library. The flaw resides in the GitHub Flavored Markdown (GFM) Table extension and can be triggered remotely without authentication by submitting specially crafted Markdown text. A fix is available in version 2.10.2.

What happened

A vulnerability tracked as CVE-2026-105830 (GHSA-3q6v-r5mr-hxv8) was published affecting league/commonmark, a PHP library for parsing Markdown. The issue is a quadratic-time denial-of-service flaw located in the block-start scan of the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() function.

Technical cause

The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption). According to the advisory, an attacker can submit a large paragraph consisting of pipe-free lines that do not start with letters. This input forces the TableStartParser::tryStart() function to repeatedly perform full-buffer strpos scans, resulting in quadratic-time processing that exhausts PHP worker CPU resources.

Why it matters

The vulnerability can be triggered by unauthenticated attackers without requiring any user interaction, meaning any application that passes untrusted user input to the CommonMark GFM Table extension could be exposed to CPU exhaustion and service degradation or outage.

Who is affected

Any application or service using league/commonmark with the GitHub Flavored Markdown Table extension enabled, within the affected version range, is potentially exposed. This includes PHP applications that render user-submitted Markdown content, such as comment systems, documentation tools, or content management platforms.

Affected versions

league/commonmark versions from 2.0.0 up to and including 2.10.1 are affected. Version 2.10.2 contains the fix.

Fixes and mitigation

The vulnerability is fixed in league/commonmark version 2.10.2. Users of affected versions (2.0.0 through 2.10.1) should update to 2.10.2 to resolve the issue.

Recommended action

Site owners and developers using league/commonmark should update to version 2.10.2 as soon as possible, particularly if the GitHub Flavored Markdown Table extension is enabled and the library processes untrusted or user-submitted Markdown input. Verify the update in dependency manifests (e.g., composer.lock) and redeploy affected services.

PatchBriefing score

6.0 / 10 · Medium

Official CVSS: 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

This advisory carries a PatchWire score of 6, reflecting a CVSS v4.0 base score of 8.7 driven primarily by high availability impact (VA:H) with no confidentiality or integrity impact. The score accounts for the fact that the vulnerability can be exploited remotely without authentication (AV:N, PR:N) and without user interaction (UI:N), increasing its contribution. There is no evidence of known exploitation in the wild or publicly available exploit code, and EPSS data was not available for this advisory, which limits the overall score despite the high CVSS base. A fix is available, which also moderates the final score.

Affected versions

league/commonmark >= 2.0.0, <= 2.10.1
vulnerable
league/commonmark ≥ 2.0.0 < 2.10.2
vulnerable
league/commonmark
vulnerable
league/commonmark >=2.0.0,<=2.10.1
vulnerable
≥ 2.10.2
patched

Reported fixes

The vulnerability is fixed in league/commonmark version 2.10.2. Users of affected versions (2.0.0 through 2.10.1) should update to 2.10.2 to resolve the issue.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • OSV.dev database
  • Packagist Security Advisories registry
  • NVD (NIST) database
Unified report
league/commonmark: Quadratic-Time Denial of Service in GFM Table Extension (CVE-2026-105830)
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email