High severity7.5NVD Advisory· Published Sep 7, 2026
CVE-2026-86435
CVE-2026-86435
Description
commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: from 1.5.0 before 2.8.4
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.