SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86428

HIGH · CVSS 7.5 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Commonmark versions prior to 2.10.0 are vulnerable to a denial of service attack through the AttributesExtension, which can be exploited by attackers submitting Markdown with multiple distinct attribute names. This results in quadratic-time processing, leading to excessive CPU resource consumption and potentially halting legitimate requests. Organizations using affected versions should prioritize updating to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86428
Severity
HIGH
CVSS
7.5
EPSS
0.28%

Original NVD Description

commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.

Related CVEs

Other vulnerabilities affecting the same vendor(s)