commonmark versions from 1.5.0 before 2.8.4 contain a...
High severity
Unreviewed
Published
Sep 7, 2026
to the GitHub Advisory Database
•
Updated Sep 7, 2026
Description
Published by the National Vulnerability Database
Sep 7, 2026
Published to the GitHub Advisory Database
Sep 7, 2026
Last updated
Sep 7, 2026
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources.
References