High severityNVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
CVE-2026-59887
Description
linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
linkify-itnpm | < 5.0.2 | 5.0.2 |
Affected products
9- Range: <5.0.2
- osv-coords8 versionspkg:apk/chainguard/gitlab-rails-ce-18.1pkg:apk/chainguard/gitlab-rails-ce-fips-19.1pkg:apk/chainguard/kibana-8.19pkg:apk/chainguard/kibana-8.19-bitnamipkg:apk/chainguard/kibana-8.19-iamguardedpkg:apk/chainguard/kibana-9.0pkg:apk/chainguard/kibana-9.0-bitnamipkg:apk/chainguard/kibana-9.0-iamguarded
< 18.1.6-r24+ 7 more
- (no CPE)range: < 18.1.6-r24
- (no CPE)range: < 19.1.3-r0
- (no CPE)range: < 8.19.18-r3
- (no CPE)range: < 8.19.18-r3
- (no CPE)range: < 8.19.18-r3
- (no CPE)range: < 9.0.8-r34
- (no CPE)range: < 9.0.8-r34
- (no CPE)range: < 9.0.8-r34
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-v245-v573-v5vmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59887ghsaADVISORY
- github.com/markdown-it/linkify-it/commit/105e5d77f7d119871d2b2d86ed208568eb3e7ffeghsax_refsource_MISCWEB
- github.com/markdown-it/linkify-it/releases/tag/5.0.2ghsax_refsource_MISCWEB
- github.com/markdown-it/linkify-it/security/advisories/GHSA-v245-v573-v5vmghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.