CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105830
HIGHCVSS 7.5NVD feed
Published 8 October 2026 · tracked since 9 October 2026
Description
league/commonmark from 2.0.0 before 2.10.2 contains a quadratic-time denial of service vulnerability in the GitHub Flavored Markdown Table extension's TableStartParser::tryStart() block-start scan. Unauthenticated attackers can submit a large paragraph of pipe-free lines not starting with letters, f
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107294 MEDIUM 6.5
- CVE-2026-107295 HIGH 7.6
- CVE-2026-107296 LOW 3.7
- CVE-2026-107297 MEDIUM 5.9
- CVE-2026-107290 MEDIUM 6.5
- CVE-2026-107291
- CVE-2026-107292 MEDIUM 6.4
- CVE-2026-107293
- CVE-2026-105436 HIGH 8.8
- CVE-2026-104077 HIGH 7.8