CVE-2026-48801
EUVD-2026-4445414.07.2026, 21:17
linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| markdown-it | linkify-it | 𝑥 < 5.0.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
Vulnerability Media Exposure