THREAT OPS › Threat News › [NVD] CVE-2026-86429 (HIGH 7.5) — The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default an
[NVD] CVE-2026-86429 (HIGH 7.5) — The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default an
CVE-2026-86429 CVSS: 7.5 HIGH Published: 2026-09-07T13:20:42.180
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub
Indicators of compromise
- CVE-2026-86429cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86429