THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8rr7-cvq3-gmfh (high) — league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension

[GHSA] GHSA-8rr7-cvq3-gmfh (high) — league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension

medgithub_advisoriesPublished 2026-09-01

GHSA-8rr7-cvq3-gmfh Severity: high CVE: None

league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension

### Impact

`AttributesExtension` ships with the library but must be explicitly registered on the `Environment`; it is not included in `CommonMarkConverter`, `GithubFlavoredMarkdownConverter`, or `GithubFlavoredMarkdownExtension`. **Applications that do no

Original source: https://github.com/advisories/GHSA-8rr7-cvq3-gmfh