GHSA-JJV6-8J6V-6J52

GHSA-JJV6-8J6V-6J52 is a high-severity security vulnerability in league/commonmark (composer), affecting versions >= 1.5.0, < 2.9.1. It is fixed in 2.9.1.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

league/commonmark: Denial of service in the SmartPunct and Attributes extensions

Workarounds

If you cannot upgrade immediately:

  • Do not register SmartPunctExtension or AttributesExtension when converting untrusted Markdown. This fully removes the affected paths.
  • If either extension is required, impose a strict maximum input length before conversion. Because the cost is quadratic, even a modest cap must be small to meaningfully bound worst-case CPU time.

Restricting conversion to trusted users, applying strict execution-time limits, and rate-limiting requests reduce exposure but are not substitutes for upgrading. Configuration options including attributes/allow, max_delimiters_per_line, max_nesting_level, html_input, and allow_unsafe_links do not mitigate these issues.

Impact

Two first-party extensions contain quadratic parsing paths. Both ship with the library but must be explicitly registered on the Environment; neither is included in CommonMarkConverter, GithubFlavoredMarkdownConverter, or GithubFlavoredMarkdownExtension. Applications that do not register SmartPunctExtension or AttributesExtension are not affected by this advisory.

1. SmartPunctExtension, quote replacement recopies the whole text node (affected from 2.0.0).

ReplaceUnpairedQuotesListener converts each unpaired Quote node back to a Text node and merges it into its neighbours via AdjacentTextMerger. The merge reads the left node's literal into a local variable, appends to that variable, and writes it back, and because the read aliases the node's string, every append copies the entire accumulated literal rather than only the bytes added. The listener runs this once per surviving unpaired quote against the same continuously growing text node, so the same buffer is fully re-copied a linear number of times.

A 1.2 MB document of alternating text segments and apostrophes takes 34.9 seconds to convert, against 0.069 seconds for the same input with the extension not registered.

Hardened configuration makes this worse rather than better: QuoteParser appends the Quote node to the AST before pushing it onto the delimiter stack, so max_delimiters_per_line removes the quote-pairing work while leaving every node the listener must process.

2. AttributesExtension, block-level attribute runs re-scan their siblings (affected from 1.5.0).

AttributesListener::findTargetAndDirection() walks the entire remaining sibling chain for every block-level Attributes node whose target is the following node. The backward half of that walk returns immediately for such nodes, and the forward half stops only at a sibling that is not itself an attributes node, which a contiguous run never provides, so a run of k nodes costs k(k-1)/2 steps.

An input placing each {#a} on its own line, with a single reference definition to keep the run contiguous, takes 28.4 seconds at 16,000 attribute blocks while producing zero bytes of output.

This is the block-level counterpart of GHSA-g2gp-3wwq-f4ph, patched in 2.9.0. That fix is incomplete: the early break it introduced is guarded on the node being an AttributesInline, so block-level Attributes nodes still re-scan. Applications that upgraded to 2.9.0 specifically to address GHSA-g2gp-3wwq-f4ph remain exposed to this variant.

3. AttributesExtension, class lists are rebuilt on every merge (affected from 1.5.0).

AttributesHelper::mergeAttributes() round-trips the accumulated class list through explode and implode on each merge. An #id attribute assigns a scalar and skips the branch entirely, but a .class attribute appends to an array which is then imploded to a string, written to the target node, and read back on the next iteration, so the ith merge pays a cost proportional to i three separate times.

{.c} repeated 32,000 times takes 33.5 seconds, against 0.26 seconds for byte-identical input using {#a}, a 130x gap that widens with input size. Both the inline and the block-level attribute paths are affected.

Overall impact. An unauthenticated attacker who can submit Markdown to an affected application can consume disproportionate CPU time with a comparatively small request, occupying PHP workers and preventing legitimate requests from completing. The impact is limited to availability: no data is disclosed, rendered output is unchanged, and no rendering restriction is bypassed.

No library-level configuration gates any of these paths. For the Attributes extension in particular, neither the attributes/allow allow-list nor the on* event-handler hardening added in 2.7.0 has any effect, because the expensive work happens while parsing and resolving the AST, before any attribute filtering or rendering takes place.

GHSA-JJV6-8J6V-6J52 has a CVSS score of 7.5 (High). The vector is network-reachable, no privileges required, and no user interaction. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (2.9.1); upgrading removes the vulnerable code path.

Affected versions

league/commonmark (>= 1.5.0, < 2.9.1)

Security releases

league/commonmark → 2.9.1 (composer)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

The issues are patched in 2.9.1 and later:

  • Adjacent text merging now appends in place instead of reading, modifying, and writing back the whole literal, so a merge costs only the bytes added. This fixes the defect for every caller, not only the SmartPunct listener.
  • AttributesListener now records the runs it has already walked, so each contiguous run of block-level attribute nodes is scanned once rather than once per node.
  • Accumulated class lists no longer pass through mergeAttributes() repeatedly; the listener holds pending attributes and joins them in a single pass.

The SmartPunct path affects 2.0.0 through 2.9.0. The Attributes paths affect 1.5.0 through 2.9.0, including releases that already contain the 2.9.0 fix for GHSA-g2gp-3wwq-f4ph. The 1.x release line is no longer supported, so its users must upgrade to 2.9.1 or later.

Frequently Asked Questions

  1. What is GHSA-JJV6-8J6V-6J52? GHSA-JJV6-8J6V-6J52 is a high-severity security vulnerability in league/commonmark (composer), affecting versions >= 1.5.0, < 2.9.1. It is fixed in 2.9.1.
  2. How severe is GHSA-JJV6-8J6V-6J52? GHSA-JJV6-8J6V-6J52 has a CVSS score of 7.5 (High). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
  3. Which versions of league/commonmark are affected by GHSA-JJV6-8J6V-6J52? league/commonmark (composer) versions >= 1.5.0, < 2.9.1 is affected.
  4. Is there a fix for GHSA-JJV6-8J6V-6J52? Yes. GHSA-JJV6-8J6V-6J52 is fixed in 2.9.1. Upgrade to this version or later.
  5. Is GHSA-JJV6-8J6V-6J52 exploitable, and should I be worried? Whether GHSA-JJV6-8J6V-6J52 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  6. What actually determines whether GHSA-JJV6-8J6V-6J52 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  7. How do I fix GHSA-JJV6-8J6V-6J52? Upgrade league/commonmark to 2.9.1 or later.

Other vulnerabilities in league/commonmark

Stop the waste.
Protect your environment with Kodem.