CVE-2026-105830: league/commonmark 2.0.0 before 2.10.2 Quadratic DoS via TableStartParser
league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() block-start scan. Unauthenticated attackers can submit a large paragraph of pipe-free lines not starting with letters, forcing repeated full-buffer strpos scans that exhaust PHP worker CPU.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using packagist/league/commonmark versions from 2.0.0 up to, but not including, 2.10.2 are affected when the GitHub Flavored Markdown Table extension processes attacker-controlled Markdown.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They need to submit a large paragraph containing pipe-free lines that do not start with letters, causing repeated full-buffer scans during block-start parsing.
What is the operational impact?
The crafted input can drive quadratic-time processing and exhaust PHP worker CPU, resulting in a denial of service.
What can be done if upgrading is not immediately possible?
The available information identifies the triggering input pattern: large paragraphs of pipe-free lines that do not start with letters. Restricting or filtering untrusted Markdown matching that pattern can reduce exposure until version 2.10.2 or later is deployed.