Allowlist Bypass Vulnerability in League CommonMark Markdown Parser
CVE-2026-33347

6.3MEDIUM

Key Information:

Vendor
CVE Published:
24 March 2026

What is CVE-2026-33347?

The League CommonMark Markdown parser has a vulnerability due to a missing hostname boundary assertion in its DomainFilteringAdapter. This issue allows an attacker to pass a domain like 'youtube.com.evil' through the allowed domain checks, posing a significant risk when 'youtube.com' is an approved domain. The vulnerability affects versions 2.3.0 up to but not including 2.8.2, which has been patched to address this issue.

Affected Version(s)

commonmark >= 2.3.0, < 2.8.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.