Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

GHSA-3Q6V-R5MR-HXV8: GHSA-3Q6V-R5MR-HXV8: Algorithmic Complexity Denial of Service in league/commonmark GFM Table Extension

GHSA-3Q6V-R5MR-HXV8: Algorithmic Complexity Denial of Service in league/commonmark GFM Table Extension Vulnerability ID: GHSA-3Q6V-R5MR-HXV8 CVSS Score: 7.5 Published: 2026-09-30 An algorithmic complexity vulnerabil

GHSA-3Q6V-R5MR-HXV8: Algorithmic Complexity Denial of Service in league/commonmark GFM Table Extension

Vulnerability ID: GHSA-3Q6V-R5MR-HXV8
CVSS Score: 7.5
Published: 2026-09-30

An algorithmic complexity vulnerability in the league/commonmark library's GitHub Flavored Markdown (GFM) Table extension allows remote, unauthenticated attackers to cause a Denial of Service (DoS) via high CPU consumption. By submitting a specially crafted Markdown payload containing an extremely long paragraph without letter characters or pipe symbols, the parser executes a quadratic-time $O(N^2)$ scanning operation that exhausts system resources.

TL;DR

Unauthenticated algorithmic complexity vulnerability in league/commonmark allows CPU resource exhaustion and Denial of Service via crafted Markdown paragraphs.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400 / CWE-1333
  • Attack Vector: Network (Unauthenticated)
  • CVSS Score: 7.5
  • Impact: Denial of Service (DoS) via CPU Exhaustion
  • Exploit Status: Proof-of-Concept (PoC) Verified
  • KEV Status: Not Listed

Affected Systems

  • PHP applications utilizing league/commonmark version 2.0.0 through 2.10.1 with GFM Table extension enabled
  • league/commonmark: >= 2.0.0, < 2.10.2 (Fixed in: 2.10.2)

Code Analysis

Commit: 5f63680

Fix quadratic-time table start parsing in TableStartParser

See patch details in code analysis section.

Exploit Details

  • GitHub: Verified PoC inputs and pathogical test suite included in the repository advisory details.

Mitigation Strategies

  • Upgrade league/commonmark to version 2.10.2 or higher.
  • Disable the TableExtension from the CommonMark environment configuration if tables are not strictly required.
  • Deploy a Web Application Firewall (WAF) rule to block large inputs with repetitive non-alphabetical lines.

Remediation Steps:

  1. Verify the currently installed version using 'composer show league/commonmark'.
  2. Update the package by running 'composer update league/commonmark' in the project root.
  3. Verify the package has been updated to 2.10.2 or later in the composer.lock file.
  4. Deploy the updated code to production and verify table rendering functions normally.

References

Read the full report for GHSA-3Q6V-R5MR-HXV8 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.