CVE-2026-30838: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-30838 is a Cross-Site Scripting (XSS) vulnerability in the league/commonmark PHP library's DisallowedRawHtml extension that allows attackers to bypass HTML tag filtering by inserting ASCII whitespace characters (newline, tab, etc.) between a disallowed tag name and its closing >. It affects versions 2.0.0 through 2.8.0 of the league/commonmark Composer package. The vulnerability was published by maintainer colinodell on March 5, 2026, and added to the GitHub Advisory Database on March 6, 2026. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Vendor Advisory).

Technical details

The root cause is improper input neutralization (CWE-79, CWE-80) in the regex used by the DisallowedRawHtml extension to detect and block disallowed HTML tags. The original regex character class [ \/>]only matched a space, forward slash, or>as valid tag name terminators, failing to account for other ASCII whitespace characters (e.g.,\n, \t) that browsers also accept as valid terminators. An attacker can craft a markdown payload such as <script\n>— where a newline separates the tag name from>— which passes through the filter undetected and is rendered as a functional<script>tag by browsers. The fix in version 2.8.1 changes the character class to[\s/>] to match all whitespace characters (GitHub Advisory, Vendor Advisory).

Impact

Successful exploitation enables stored or reflected XSS attacks against users of any application that relies solely on the DisallowedRawHtml extension to sanitize untrusted markdown input. An attacker can inject and execute arbitrary JavaScript in victims' browsers, potentially leading to session hijacking, credential theft, unauthorized actions on behalf of the victim, or further client-side attacks. Applications that additionally pass rendered HTML through a dedicated sanitizer such as HTML Purifier are not affected. Availability is not impacted by this vulnerability (GitHub Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-30838 as of the available data. The EPSS score is approximately 0.047% (4th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to submit crafted markdown content to an application that renders it for other users, and a victim must view the rendered output — making it a low-complexity but user-interaction-dependent attack (GitHub Advisory).

Exploitation steps

  1. Identify a target application: Find a web application that uses league/commonmark versions 2.0.0–2.8.0 with the DisallowedRawHtml extension enabled to process untrusted user-supplied markdown (e.g., comment fields, wiki pages, issue trackers).
  2. Craft a bypass payload: Construct a markdown snippet containing a disallowed HTML tag (e.g., <script>) with an ASCII whitespace character inserted between the tag name and the closing >, such as:
    <script
    >alert(document.cookie)</script
    >
  3. Submit the payload: Post the crafted markdown to the target application through any input field that accepts and renders markdown (e.g., a comment, bio, or post body).
  4. Trigger victim execution: When another user (or an administrator) views the page containing the rendered markdown, the injected script executes in their browser context, enabling session token theft, credential harvesting, or further client-side attacks (GitHub Advisory, Vendor Advisory).

Indicators of compromise

  • Logs: Web server or application logs showing user-submitted content containing HTML tags with embedded whitespace characters (e.g., <script\n>, <iframe\t>) in markdown input fields.
  • Application Data: Stored markdown content in the database containing disallowed tag names followed by newline (\n), tab (\t), or other whitespace before the closing > (e.g., <script\n>, <object\r>).
  • Network: Outbound requests from victim browsers to attacker-controlled domains (e.g., for cookie exfiltration) originating from pages that render user-supplied markdown.
  • Browser/Client: Unexpected JavaScript execution or redirects occurring when users view markdown-rendered content pages.

Mitigation and workarounds

The vulnerability is fixed in league/commonmark version 2.8.1; operators should upgrade immediately via Composer (composer update league/commonmark). As a workaround, set the html_input configuration option to 'escape' or 'strip' to disable all raw HTML processing, though this is broader than the DisallowedRawHtml extension's intended scope. Additionally, passing all rendered HTML output through a dedicated HTML sanitizer such as HTML Purifier before serving it to users is strongly recommended as a defense-in-depth measure regardless of the patch status (GitHub Advisory, Vendor Advisory).

Community reactions

Red Hat acknowledged the vulnerability and published a CVE entry on March 9, 2026 (Red Hat CVE). Tenable released Nessus detection plugins (IDs 301662 and 309186) for the vulnerability. Ubuntu issued a security advisory (USN-8194-1) covering league/commonmark, and downstream projects such as Snipe-IT released updated versions (v8.4.1) incorporating the fix. Community coverage was noted on security aggregators and social platforms shortly after disclosure.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

php-league-commonmark: 2.3.9-1+deb12u1

Fixed

sid

php-league-commonmark: 2.8.1-1

Fixed

trixie

php-league-commonmark: 2.7.0-1+deb13u1

Fixed

Ubuntu

Fixed

devel

php-league-commonmark

Affected

focal (esm-apps)

php-league-commonmark: 1.3.1-1ubuntu2+esm1

Fixed

jammy

php-league-commonmark

Affected

jammy (esm-apps)

php-league-commonmark: 1.6.7-1ubuntu0.1~esm1

Fixed

noble

php-league-commonmark

Affected

noble (esm-apps)

php-league-commonmark: 2.4.2-2ubuntu0.1~esm1

Fixed

resolute

php-league-commonmark

Affected

resolute (esm-apps)

php-league-commonmark

Affected

Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management