CVE-2026-105830: league/commonmark 2.0.0 before 2.10.2 Quadratic DoS via TableStartParser

Published Oct 8, 2026
·
Updated

league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() block-start scan. Unauthenticated attackers can submit a large paragraph of pipe-free lines not starting with letters, forcing repeated full-buffer strpos scans that exhaust PHP worker CPU.

Affected Software

1 affected component
packagist/league/commonmark>=2.0.0<2.10.2

Event History

Oct 8, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using packagist/league/commonmark versions from 2.0.0 up to, but not including, 2.10.2 are affected when the GitHub Flavored Markdown Table extension processes attacker-controlled Markdown.

2

What does an attacker need to exploit it?

An attacker does not need authentication or user interaction. They need to submit a large paragraph containing pipe-free lines that do not start with letters, causing repeated full-buffer scans during block-start parsing.

3

What is the operational impact?

The crafted input can drive quadratic-time processing and exhaust PHP worker CPU, resulting in a denial of service.

4

What can be done if upgrading is not immediately possible?

The available information identifies the triggering input pattern: large paragraphs of pipe-free lines that do not start with letters. Restricting or filtering untrusted Markdown matching that pattern can reduce exposure until version 2.10.2 or later is deployed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203