Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33347

Опубликовано: 24 мар. 2026
Источник: debian
EPSS Низкий

Описание

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-league-commonmarkfixed2.8.2-1package
php-league-commonmarkfixed2.7.0-1+deb13u1trixiepackage
php-league-commonmarkfixed2.3.9-1+deb12u1bookwormpackage
php-league-commonmarkpostponedbullseyepackage

Примечания

  • https://github.com/thephpleague/commonmark/security/advisories/GHSA-hh8v-hgvp-g3f5

  • Fixed by: https://github.com/thephpleague/commonmark/commit/59fb075d2101740c337c7216e3f32b36c204218b (2.8.2)

EPSS

Процентиль: 15%
0.00241
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
5 месяцев назад

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.

CVSS3: 6.1
nvd
5 месяцев назад

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.

github
5 месяцев назад

league/commonmark has an embed extension allowed_domains bypass

EPSS

Процентиль: 15%
0.00241
Низкий