Description
linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.
Published: 2026-07-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

linkify‑it is a links recognition library with full Unicode support. The public API LinkifyIt.prototype.match has O(N²) complexity for inputs that contain many fuzzy links or email patterns, because the JavaScript‑level scan loop repeatedly slices the input and re‑runs unanchored regex searches on progressively shorter tails. When a service synchronously renders untrusted Markdown with linkify:true on a request hot path, a tens‑of‑KB payload can trigger a worker‑process denial of service. This vulnerability is classified as CWE‑1333 and was fixed in version 5.0.1.

Affected Systems

All installations of linkify‑it versions earlier than 5.0.1 that are used with markdown‑it or other Markdown rendering frameworks, when the linkify option is enabled for user supplied content, are affected. It is inferred that other Markdown rendering frameworks could also be impacted because many such frameworks may depend on linkify‑it, but the data does not explicitly state that they are affected. Any service that synchronously renders such Markdown in response to a request is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score of less than 1% suggests the probability of exploitation is very low at present, and the vulnerability is not listed in CISA’s KEV catalog. Attackers only need the ability to send a Markdown payload containing many potential links or email patterns to a vulnerable endpoint that processes Markdown with linkify enabled. No special privileges or access are required beyond the ability to send the payload, making the vulnerability exploitable in many exposed services.

Generated by OpenCVE AI on August 3, 2026 at 03:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade linkify‑it to version 5.0.1 or later.
  • If an immediate upgrade is not possible, disable or limit linkify processing for untrusted Markdown by turning off the linkify option or restricting the size or complexity of the input passed to the renderer.
  • Implement request‑level throttling or rate limiting for endpoints that render Markdown to bound CPU usage per client.

Generated by OpenCVE AI on August 3, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-22p9-wv53-3rq4 LinkifyIt#match scan loop has quadratic algorithmic complexity
History

Thu, 16 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 15 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Markdown-it
Markdown-it linkify-it
Vendors & Products Markdown-it
Markdown-it linkify-it

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.
Title linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop
Weaknesses CWE-1333
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Markdown-it Linkify-it
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-15T12:56:15.250Z

Reserved: 2026-05-22T20:18:20.367Z

Link: CVE-2026-48801

cve-icon Vulnrichment

Updated: 2026-07-15T12:55:56.140Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-14T20:03:56Z

Links: CVE-2026-48801 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity