league/commonmark Security Advisories for 2.9.0 (4)
-
[HIGH] league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
PKSA-zyf5-hrxv-hrd7 GHSA-8rr7-cvq3-gmfh
Affected version: >=1.5.0,<2.10.0
Reported by:
GitHub -
[HIGH] league/commonmark: Denial of service in the SmartPunct and Attributes extensions
PKSA-nv44-1b4d-6gjg GHSA-jjv6-8j6v-6j52
Affected version: >=1.5.0,<2.9.1
Reported by:
GitHub -
[HIGH] league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
PKSA-kr3s-894t-g5w2 GHSA-f8fg-pg57-v4j8
Affected version: >=2.7.0,<2.9.1
Reported by:
GitHub -
[HIGH] league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
PKSA-9q1p-3s19-bp1q GHSA-j8pm-gj4c-rq4x
Affected version: >=0.6.0,<2.9.1
Reported by:
GitHub