Security Advisory

CVE-2026-86432

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-07 12:53:51
Last updated 2026-09-07 12:53:51
Assigner VulnCheck
CVSS score 6.9
State PUBLISHED

Description

commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources.