CyberRota Analysis
AI-GeneratedVersions of league/commonmark prior to 2.9.1 are vulnerable to multiple denial of service attacks due to inefficient handling of fenced code blocks, reference link labels, and emphasis delimiters. Attackers can exploit these vulnerabilities by submitting specially crafted Markdown inputs, leading to excessive CPU consumption and disruption of legitimate service requests. Organizations using affected versions should prioritize upgrading to mitigate the risk of service outages.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing.
Related CVEs
Other vulnerabilities affecting the same vendor(s)