CVE-2026-33347
EUVD-2026-2007924.03.2026, 20:16
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| thephpleague | commonmark | 2.3.0 ≤ 𝑥 < 2.8.2 |
𝑥
= Vulnerable software versions
Debian Releases