Vulnerabilities
CVE-2026-30838 - league/commonmark: DisallowedRawHtml extension bypass via whitespace in HTML tag...
CVE ID :CVE-2026-30838 Published : March 7, 2026, 4:15 p.m. | 1 hour, 2 minutes ago Description :league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. For example,