highCVSS 7.5Vulnerability

GHSA-3q6v-r5mr-hxv8

## Summary `league/commonmark`'s GitHub Flavored Markdown Table extension registers `TableStartParser` as a block-start parser. While a paragraph is the active block, the core block parser calls `TableStartParser::tryStart()` on every non-blank line. Its first action fetches the entire growing paragraph buffer via `getParagraphContent()` and runs `strpos($paragraph, '|')` across all of it. For a paragraph of M pipe-free lines, line k rescans about k lines of buffer, so total work is 1+2+...+M, which is O(M^2). An unauthenticated user who submits a single large paragraph of pipe-free lines that do not begin with a letter (see Attack Chain) to any service that converts untrusted Markdown with `GithubFlavoredMarkdownConverter` (or any environment that enables `TableExtension`) drives seconds to tens of seconds of single-core CPU that grows quadratically with body size, enough to exhaust worker processes and deny service. ## Root Cause The GFM table detector performs a per-line "quick check" against the whole accumulated paragraph rather than only the portion that could form a table header. A paragraph never closes while non-blank lines keep arriving, so its buffer grows without bound, and the quick check rescans the entire buffer on each line. Only the paragraph's last line can ever be a table header (it is extracted separately via `strrpos`/`substr`), so scanning the full multi-line buffer for a pipe on every line is unnecessary work and creates quadratic time complexity. There is no input-size cap and the default nesting limit is not reached, so nothing bounds the scan. ```text Affected function: League\CommonMark\Extension\Table\TableStartParser::tryStart Location: src/Extension/Table/TableStartParser.php:35-38 $paragraph = $parserState->getParagraphContent(); // returns the FULL growing buffer if ($paragraph === null || \strpos($paragraph, '|') === false) { return BlockStart::none(); // strpos scans whole buffer each li

Properties

summary
league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan
severity
high
cvss_score
7.5
retrieved_at
2026-09-30T23:58:31+00:00
ghsa_published
2026-09-30T15:36:13Z
source_url
https://github.com/advisories/GHSA-3q6v-r5mr-hxv8
ghsa_updated
2026-09-30T15:36:17Z
ghsa_id
GHSA-3q6v-r5mr-hxv8
last_source
GitHub Advisory Database
cve_id
GHSA-3q6v-r5mr-hxv8
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-30T23:58:31+00:00
is_ghsa_only
true

Related Entities (5)

HAS_WEAKNESS (2)

→[Weakness]Uncontrolled Resource Consumption
→[Weakness]Inefficient Algorithmic Complexity

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]composer/league/commonmark

AFFECTS (1)

→[Software]composer/league/commonmark

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-3q6v-r5mr-hxv8 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal