← Back to the live CVE advisory feed

CVE-2026-86429: commonmark

Severity
8.7 (HIGH)
Vendor
THEPHPLEAGUE
Affected versions
1.5.0 through before 2.9.1
Fixed version
2.9.1
Patch status
Patched
Published
2026-09-07T13:20:42.180
Modified
2026-09-07T13:20:42.180

Why it matters

This matters because the affected product may be exploitable without valid credentials. Internet-facing deployments should be reviewed first.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Treat internet-facing systems as higher priority.

Technical summary

The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Fixed in 2.9.1.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 08, 2026 04:00 AM UTC
254 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-75650
Adobe Commerce PATCH
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-44756
SAP Extended Passport (EPP) Processing
Reporter: CNA
10
CRITICAL
VIEW RECORD
CVE-2026-76578
Red Hat Enterprise Linux 10
Reporter: SECALERT
9.8
CRITICAL
VIEW RECORD
CVE-2026-18922
Red Hat Directory Server 11.7 E4S for RHEL 8 PATCH
Reporter: SECALERT
9.8
CRITICAL
VIEW RECORD
CVE-2026-7861
CSM (Customer Service Management)
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-86478
Product identification pending PATCH
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-86480
Product identification pending PATCH
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-58240
SAP NetWeaver (Message Server)
Reporter: CNA
9.8
CRITICAL
VIEW RECORD
CVE-2026-61410
Product identification pending PATCH
Reporter: SECURITY_ALERT
9.4
CRITICAL
VIEW RECORD
CVE-2026-6223
BiHayat App
Reporter: ILETISIM
9.4
CRITICAL
VIEW RECORD
CVE-2026-76969
SAP Cloud Application Programming Model (CAP)
Reporter: CNA
9.4
CRITICAL
VIEW RECORD
CVE-2026-86296
DIR-822A
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-80238
Product identification pending PATCH
Reporter: SECURITY_ALERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-86543
knowns PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-86426
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-66768
SAP NetWeaver (SAP GUI for Java)
Reporter: CNA
9
CRITICAL
VIEW RECORD
CVE-2026-86404
Product identification pending
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-86482
Product identification pending PATCH
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2026-86542
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-14297
nRF Connect SDK
Reporter: 30A5E7FB-040D-440A-8CDF-A4A2068CE72E
8.7
HIGH
VIEW RECORD
CVE-2026-84732
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-19204
Product identification pending
Reporter: EMO
8.7
HIGH
VIEW RECORD
CVE-2022-51017
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86427
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86428
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86429
commonmark PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86430
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86433
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86434
commonmark PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86435
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86452
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.7
HIGH
VIEW RECORD
CVE-2026-86439
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86538
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-79697
WISE-6610-NB PATCH
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-79698
WISE-6610-NB PATCH
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-86299
RE7000
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-86437
laradashboard PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-86438
laradashboard PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-86509
DIR-895L
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-86510
DIR-822A
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-84226
Product identification pending
Reporter: SECURITY
8.5
HIGH
VIEW RECORD
CVE-2026-86492
Product identification pending PATCH
Reporter: CVE
8.5
HIGH
VIEW RECORD
CVE-2026-86540
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-76958
Product identification pending
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-19843
Red Hat Directory Server 11.7 E4S for RHEL 8 PATCH
Reporter: SECALERT
8.4
HIGH
VIEW RECORD
CVE-2026-86502
Product identification pending PATCH
Reporter: CVE
8.4
HIGH
VIEW RECORD
CVE-2026-84173
Product identification pending
Reporter: EMO
8.3
HIGH
VIEW RECORD
CVE-2026-86297
DIR-605
Reporter: CNA
8.2
HIGH
VIEW RECORD
CVE-2026-79645
Product identification pending PATCH
Reporter: SECURITY_ALERT
8.2
HIGH
VIEW RECORD
CVE-2026-82586
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
8.2
HIGH
VIEW RECORD
CVE-2026-82753
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
8.2
HIGH
VIEW RECORD
CVE-2026-79678
Red Hat Enterprise Linux 10
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-80132
Product identification pending PATCH
Reporter: SECURITY_ALERT
8.1
HIGH
VIEW RECORD
CVE-2026-86479
Product identification pending PATCH
Reporter: CVE
8.1
HIGH
VIEW RECORD
CVE-2026-80166
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2026-86504
Product identification pending PATCH
Reporter: CVE
7.8
HIGH
VIEW RECORD
CVE-2026-76967
Product identification pending
Reporter: CNA
7.8
HIGH
VIEW RECORD
CVE-2026-84256
Product identification pending
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-80134
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.7
HIGH
VIEW RECORD
CVE-2026-86494
Product identification pending PATCH
Reporter: CVE
7.7
HIGH
VIEW RECORD
CVE-2026-86498
Product identification pending PATCH
Reporter: CVE
7.7
HIGH
VIEW RECORD
CVE-2026-66767
Product identification pending
Reporter: CNA
7.7
HIGH
VIEW RECORD
CVE-2026-19397
Control Center Express Agent
Reporter: 54BF65A7-A193-42D2-B1BA-8E150D3C35E1
7.7
HIGH
VIEW RECORD
CVE-2026-79639
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.6
HIGH
VIEW RECORD
CVE-2026-14296
nRF54H20
Reporter: 30A5E7FB-040D-440A-8CDF-A4A2068CE72E
7.5
HIGH
VIEW RECORD
CVE-2026-80135
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.5
HIGH
VIEW RECORD
CVE-2026-14444
WP Fusion (Pro)
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-76560
Red Hat Directory Server 11.7 E4S for RHEL 8 PATCH
Reporter: SECALERT
7.5
HIGH
VIEW RECORD
CVE-2026-18355
Product identification pending
Reporter: SECALERT
7.5
HIGH
VIEW RECORD
CVE-2026-18453
Red Hat Directory Server 11.7 E4S for RHEL 8 PATCH
Reporter: SECALERT
7.5
HIGH
VIEW RECORD
CVE-2026-6377
Product identification pending
Reporter: ILETISIM
7.5
HIGH
VIEW RECORD
CVE-2026-78480
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.5
HIGH
VIEW RECORD
CVE-2026-80133
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.4
HIGH
VIEW RECORD
CVE-2026-80131
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.4
HIGH
VIEW RECORD
CVE-2026-80164
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.4
HIGH
VIEW RECORD
CVE-2026-79644
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.4
HIGH
VIEW RECORD
CVE-2026-61409
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.3
HIGH
VIEW RECORD
CVE-2026-79643
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.3
HIGH
VIEW RECORD
CVE-2026-79691
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.3
HIGH
VIEW RECORD
CVE-2026-6431
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
Reporter: SECURITY
7.2
HIGH
VIEW RECORD
CVE-2026-80127
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.2
HIGH
VIEW RECORD
CVE-2026-86541
Product identification pending PATCH
Reporter: DISCLOSURE
7.2
HIGH
VIEW RECORD
CVE-2026-86544
Product identification pending PATCH
Reporter: DISCLOSURE
7.2
HIGH
VIEW RECORD
CVE-2026-86347
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
7.1
HIGH
VIEW RECORD
CVE-2022-51010
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2022-51012
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2022-51013
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2022-51014
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2022-51015
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2022-51018
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-86408
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
7.1
HIGH
VIEW RECORD
CVE-2026-80130
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.1
HIGH
VIEW RECORD
CVE-2026-86419
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
7
HIGH
VIEW RECORD
CVE-2026-84186
PrestaShop
Reporter: CVE-COORDINATION
6.9
MEDIUM
VIEW RECORD
CVE-2026-78325
Product identification pending
Reporter: B2FA7FCC-7D08-41F0-853B-11242C5539DB
6.9
MEDIUM
VIEW RECORD
CVE-2026-86303
markdown
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-86431
commonmark PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-86432
Product identification pending PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-86317
llama.cpp
Reporter: CNA
6.9
MEDIUM
VIEW RECORD
CVE-2026-86539
Product identification pending
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.