CyberRota Analysis
AI-GeneratedCommonmark versions prior to 2.10.0 are vulnerable to a denial of service attack through the AttributesExtension, which can be exploited by attackers submitting Markdown with multiple distinct attribute names. This results in quadratic-time processing, leading to excessive CPU resource consumption and potentially halting legitimate requests. Organizations using affected versions should prioritize updating to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.
Related CVEs
Other vulnerabilities affecting the same vendor(s)