Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2024-58382: Inefficient Algorithmic Complexity in thephpleague commonmarkCVE-2024-58382 0 league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case performance, and sending multiple requests in parallel exhausts CPU resources and PHP-FPM processes. Join the discussion | CVE Database V5 | 09/09/2026, 13:31:56 UTC Added: 09/09/2026, 13:37:42 UTC |
CVE-2026-86435: Inefficient Algorithmic Complexity in thephpleague commonmarkCVE-2026-86435 0 commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources. Join the discussion | CVE Database V5 | 09/07/2026, 12:53:53 UTC Added: 09/07/2026, 13:07:58 UTC |
CVE-2026-86434: Inefficient Algorithmic Complexity in thephpleague commonmarkCVE-2026-86434 0 league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service. Join the discussion | CVE Database V5 | 09/07/2026, 12:53:53 UTC Added: 09/07/2026, 13:07:58 UTC |
CVE-2026-86433: Inefficient Algorithmic Complexity in thephpleague commonmarkCVE-2026-86433 0 commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where AttributesListener::findTargetAndDirection() performs quadratic-time sibling list scanning. Unauthenticated attackers can submit approximately 32 KB of repeated attribute blocks to cause parsing to take over 5 seconds, exhausting server resources. Join the discussion | CVE Database V5 | 09/07/2026, 12:53:52 UTC Added: 09/07/2026, 13:07:58 UTC |
CVE-2026-86432: Asymmetric Resource Consumption (Amplification) in thephpleague commonmarkCVE-2026-86432 0 commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause quadratic memory consumption and output amplification, exhausting server resources. Join the discussion | CVE Database V5 | 09/07/2026, 12:53:51 UTC Added: 09/07/2026, 13:07:56 UTC |
CVE-2026-86431: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in thephpleague commonmarkCVE-2026-86431 0 league/commonmark (thephpleague/commonmark) versions >= 2.7.0 and < 2.9.1 contain a cross-site scripting vulnerability in the AttributesExtension. Prefixing an attribute name with a single U+000C form feed byte (e.g. {\x0Conclick="alert(1)"}) bypasses the AttributesHelper::filterAttributes() 'on*' event-handler filter because PHP's trim() does not strip U+000C, causing the attribute to be written verbatim into the output where browsers parse it as a genuine event handler. The same prefix also defeats the allow_unsafe_links check, allowing javascript: URIs through href/src attributes even when allow_unsafe_links is false. Exploitation requires processing untrusted Markdown with the AttributesExtension enabled; the injected script executes when the rendered HTML is viewed. Fixed in 2.9.1. Join the discussion | CVE Database V5 | 09/07/2026, 12:53:51 UTC Added: 09/07/2026, 13:07:56 UTC |
CVE-2026-86430: Inefficient Algorithmic Complexity in thephpleague commonmarkCVE-2026-86430 0 league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing. Join the discussion | CVE Database V5 | 09/07/2026, 12:53:50 UTC Added: 09/07/2026, 13:07:56 UTC |
CVE-2026-86429: Inefficient Algorithmic Complexity in thephpleague commonmarkCVE-2026-86429 0 The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Fixed in 2.9.1. Join the discussion | CVE Database V5 | 09/07/2026, 12:53:49 UTC Added: 09/07/2026, 13:07:56 UTC |
CVE-2026-86428: Inefficient Algorithmic Complexity in thephpleague commonmarkCVE-2026-86428 0 commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing. Join the discussion | CVE Database V5 | 09/07/2026, 12:53:49 UTC Added: 09/07/2026, 13:07:56 UTC |
Showing 1 to 9 of 9 results