CVE-2026-48801

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.

  • Published Jul 14, 2026
  • CVSS 8.7 high
  • 0.5% chance of exploitation in the next 30 days (EPSS)
  • Public exploit code is available
  • A fix is available

Affected software

In the news

CVE-2026-48801 at the National Vulnerability Database