THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86429 (HIGH 7.5) — The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default an

[NVD] CVE-2026-86429 (HIGH 7.5) — The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default an

mednvdPublished 2026-09-07

CVE-2026-86429 CVSS: 7.5 HIGH Published: 2026-09-07T13:20:42.180

The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86429