Allowlist Bypass Vulnerability in League CommonMark Markdown Parser
CVE-2026-33347
6.3MEDIUM
What is CVE-2026-33347?
The League CommonMark Markdown parser has a vulnerability due to a missing hostname boundary assertion in its DomainFilteringAdapter. This issue allows an attacker to pass a domain like 'youtube.com.evil' through the allowed domain checks, posing a significant risk when 'youtube.com' is an approved domain. The vulnerability affects versions 2.3.0 up to but not including 2.8.2, which has been patched to address this issue.
Affected Version(s)
commonmark >= 2.3.0, < 2.8.2
