Threats Tagged 'ghsa-mh25-x5hq-wrqp'
View all threats tagged with 'ghsa-mh25-x5hq-wrqp'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-mh25-x5hq-wrqp'
Click on any threat for detailed analysis and mitigation recommendations
league/commonmark: Denial of service via colliding heading slugs 0 A denial of service vulnerability exists in league/commonmark versions 2.0.0 through 2.8.x due to a quadratic algorithmic complexity in the UniqueSlugNormalizer::normalize() function. This function restarts its search for unique slug suffixes from 1 on every collision, causing O(K²) CPU cost for K colliding slugs. The issue affects processing of headings and footnotes when certain extensions are enabled, allowing an attacker to cause significant CPU consumption and service disruption without authentication. Workarounds include disabling slug uniqueness or affected extensions, but upgrading to a patched release is recommended. Join the discussion | GCVE Database | 08/06/2026, 20:41:45 UTC Added: 08/07/2026, 05:57:21 UTC |
Showing 1 to 1 of 1 result