GHSA-3Q6V-R5MR-HXV8: GHSA-3Q6V-R5MR-HXV8: Algorithmic Complexity Denial of Service in league/commonmark GFM Table Extension
GHSA-3Q6V-R5MR-HXV8: Algorithmic Complexity Denial of Service in league/commonmark GFM Table Extension Vulnerability ID: GHSA-3Q6V-R5MR-HXV8 CVSS Score: 7.5 Published: 2026-09-30 An algorithmic complexity vulnerabil
GHSA-3Q6V-R5MR-HXV8: Algorithmic Complexity Denial of Service in league/commonmark GFM Table Extension
Vulnerability ID: GHSA-3Q6V-R5MR-HXV8
CVSS Score: 7.5
Published: 2026-09-30
An algorithmic complexity vulnerability in the league/commonmark library's GitHub Flavored Markdown (GFM) Table extension allows remote, unauthenticated attackers to cause a Denial of Service (DoS) via high CPU consumption. By submitting a specially crafted Markdown payload containing an extremely long paragraph without letter characters or pipe symbols, the parser executes a quadratic-time $O(N^2)$ scanning operation that exhausts system resources.
TL;DR
Unauthenticated algorithmic complexity vulnerability in league/commonmark allows CPU resource exhaustion and Denial of Service via crafted Markdown paragraphs.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-400 / CWE-1333
- Attack Vector: Network (Unauthenticated)
- CVSS Score: 7.5
- Impact: Denial of Service (DoS) via CPU Exhaustion
- Exploit Status: Proof-of-Concept (PoC) Verified
- KEV Status: Not Listed
Affected Systems
- PHP applications utilizing league/commonmark version 2.0.0 through 2.10.1 with GFM Table extension enabled
-
league/commonmark: >= 2.0.0, < 2.10.2 (Fixed in:
2.10.2)
Code Analysis
Commit: 5f63680
Fix quadratic-time table start parsing in TableStartParser
See patch details in code analysis section.
Exploit Details
- GitHub: Verified PoC inputs and pathogical test suite included in the repository advisory details.
Mitigation Strategies
- Upgrade league/commonmark to version 2.10.2 or higher.
- Disable the TableExtension from the CommonMark environment configuration if tables are not strictly required.
- Deploy a Web Application Firewall (WAF) rule to block large inputs with repetitive non-alphabetical lines.
Remediation Steps:
- Verify the currently installed version using 'composer show league/commonmark'.
- Update the package by running 'composer update league/commonmark' in the project root.
- Verify the package has been updated to 2.10.2 or later in the composer.lock file.
- Deploy the updated code to production and verify table rendering functions normally.
References
Read the full report for GHSA-3Q6V-R5MR-HXV8 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.