Junglewise Threat Intelligence

CVE-2026-86432: commonmark XmlRenderer denial of service via nested XML indentation

CVE-2026-86432 · Severity: medium · CVSS 5.3 · Published 2026-09-07

Technologies: The PHP League CommonMark. Vendors: The PHP League.

Executive brief

The commonmark library is a popular Markdown-to-XML converter used by web applications to process user-supplied content. A flaw in its XML rendering feature causes quadratic memory consumption when processing deeply nested Markdown structures, allowing attackers to exhaust server resources through a single request containing nested blockquotes or crafted AST trees.

Technical details

The XmlRenderer component in commonmark emits indentation whitespace proportional to tree depth for every XML tag opening and closing, resulting in O(n²) bytes of memory and output for a tree of depth n. Attackers can trigger this through the MarkdownToXmlConverter with deeply nested Markdown (e.g. repeated blockquotes via str_repeat('> ', $depth)) or by passing a malicious AST directly to XmlRenderer::renderDocument(). The parser's max_nesting_level configuration can bound parser-generated trees but does not constrain programmatically built ASTs, and the default limit is high enough to reach damaging sizes. This amplification vulnerability affects all versions from 2.0.0 through 2.8.3; version 2.9.0 patches the issue. The HTML renderer does not emit depth-proportional indentation and is not vulnerable.

Affected products

  • The PHP League commonmark 2.0.0 to 2.8.3

Timeline

  • 2026-08-03: disclosed
  • 2026-09-07: patched: Version 2.9.0 released

References

Related threats