SCA: security update for league/commonmark (GHSA-2q4p-g7hv-5rgv)

high Tenable Cloud Security Plugin ID 445775

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0,
specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting,
because several parsing paths repeatedly rescan growing portions of a line to translate between character
positions and byte positions, and the Autolink extension can also copy and validate the remaining line at
every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume
disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0.
(CVE-2026-71488)

Solution

Update the league/commonmark library and its related packages to version 2.9.0 or later.

See Also

https://github.com/advisories/GHSA-2q4p-g7hv-5rgv

Plugin Details

Severity: High

ID: 445775

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/7/2026

Updated: 8/7/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-71488

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 8/6/2026

Reference Information

CVE: CVE-2026-71488