High severity7.5NVD Advisory· Published Jul 8, 2026· Updated Aug 26, 2026
CVE-2026-59887
CVE-2026-59887
Description
linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
linkify-itnpm | < 5.0.2 | 5.0.2 |
Affected products
12- osv-coords11 versionspkg:apk/chainguard/gitlab-rails-ce-18.1pkg:apk/chainguard/gitlab-rails-ce-19.3pkg:apk/chainguard/kibana-8.19pkg:apk/chainguard/gitlab-rails-ce-fips-19.1pkg:apk/chainguard/kibana-8.19-bitnamipkg:apk/chainguard/kibana-8.19-iamguardedpkg:apk/chainguard/kibana-9.0-bitnamipkg:apk/chainguard/kibana-9.0pkg:apk/chainguard/kibana-9.0-iamguardedpkg:apk/chainguard/gitlab-rails-ce-fips-19.2pkg:apk/chainguard/gitlab-rails-ce-fips-18.1
< 18.1.6-r24+ 10 more
- (no CPE)range: < 18.1.6-r24
- (no CPE)range: < 19.3.1-r6
- (no CPE)range: < 8.19.18-r3
- (no CPE)range: < 19.1.3-r0
- (no CPE)range: < 8.19.18-r3
- (no CPE)range: < 8.19.18-r3
- (no CPE)range: < 9.0.8-r34
- (no CPE)range: < 9.0.8-r34
- (no CPE)range: < 9.0.8-r34
- (no CPE)range: < 19.2.1-r2
- (no CPE)range: < 18.1.6-r81
- Range: <5.0.2
Patches
Vulnerability mechanics
References
5- github.com/markdown-it/linkify-it/commit/105e5d77f7d119871d2b2d86ed208568eb3e7ffenvdPatchWEB
- github.com/markdown-it/linkify-it/security/advisories/GHSA-v245-v573-v5vmnvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-v245-v573-v5vmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59887ghsaADVISORY
- github.com/markdown-it/linkify-it/releases/tag/5.0.2nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.