VYPR
High severity7.5OSV Advisory· Published Jul 14, 2026· Updated Aug 6, 2026

CVE-2026-48801

CVE-2026-48801

Description

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
linkify-itnpm
< 5.0.15.0.1

Affected products

24

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.