Beveiligingsadvies

CVE-2026-33347

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-24 19:26:23
Laatst bijgewerkt 2026-03-26 19:52:12
Toegewezen door GitHub_M
CVSS-score 6.3
Status PUBLISHED

Beschrijving

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.