Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-33347

5 месяцев назад

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-33347

5 месяцев назад

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-33347

5 месяцев назад

league/commonmark is a PHP Markdown parser. From version 2.3.0 to befo ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-hh8v-hgvp-g3f5

5 месяцев назад

league/commonmark has an embed extension allowed_domains bypass

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33347

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.

CVSS3: 6.1
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-33347

league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.

CVSS3: 6.1
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-33347

league/commonmark is a PHP Markdown parser. From version 2.3.0 to befo ...

CVSS3: 6.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-hh8v-hgvp-g3f5

league/commonmark has an embed extension allowed_domains bypass

0%
Низкий
5 месяцев назад

Уязвимостей на страницу