-
High
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
Reported
1 Sep 2026, 20:28
View advisory
-
High
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
Reported
1 Sep 2026, 20:21
View advisory
-
High
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
Reported
1 Sep 2026, 20:18
View advisory
-
High
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
Reported
1 Sep 2026, 20:17
View advisory
-
Medium
league/commonmark: Denial of service via deeply nested XML output
Reported
6 Aug 2026, 20:42
View advisory
-
High
league/commonmark: Denial of service via colliding heading slugs
Reported
6 Aug 2026, 20:41
View advisory
-
High
league/commonmark: Denial of service via duplicate footnote definitions
Reported
6 Aug 2026, 20:40
View advisory
-
High
league/commonmark: Denial of service via adjacent inline attribute blocks
Reported
6 Aug 2026, 20:39
View advisory
-
CVE-2026-71488
High
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
Reported
6 Aug 2026, 20:37
View advisory
-
CVE-2026-71478
Medium
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
Reported
6 Aug 2026, 20:30
View advisory