🛡️ CVE-2026-59887 — linkify-it

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-407 NVD
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

linkify-it: Quadratic-complexity DoS via the mailto: validator scan-loop on attacker text

Summary

linkify-it's schema-scan loop (.test() / .match(), the documented public API) invokes the mailto:

schema validator at every mailto: occurrence in the input text. For each occurrence the validator does

text.slice(pos) (an O(n) copy) and runs an email regex whose local-part class src_email_name greedily

scans the entire remaining tail (O(n)) before failing. With N mailto: occurrences that is

N × O(n) = O(n²). Because linkify-it runs on arbitrary user text (markdown-it feeds it whole documents

when linkify:true), an unauthenticated attacker can block the single-threaded event loop for many seconds

with a small input. No length bound (unlike an HTTP header).

Root cause — index.mjs + lib/re.mjs

```js

// index.mjs (mailto validator) — runs at every "mailto:" hit

'mailto:': { validate: function (text, pos, self) {

const tail = text.slice(pos) // O(n) copy per hit

if (!self.re.mailto) self.re.mailto = new RegExp('^' + self.re.src_email_name + '@' + self.re.src_host_strict, 'i')

if (self.re.mailto.test(tail)) { ... } // scans the whole O(n) tail

return 0

}}

// lib/re.mjs:91-93 — every char of "mailto:" (incl. ':','-',';') is in this class:

re.src_email_name = '[\\-;:&=\\+\\$,\\.a-zA-Z0-9_][\\-;:&=\\+\\$,\\"\\.a-zA-Z0-9_]*'

```

The while ((m = re.exec(text)) !== null) { …testSchemaAt… } scan loop calls the validator at each

mailto: hit; src_email_name greedily consumes the whole tail (all chars are in its class) then fails for

lack of @. http:/https: do NOT blow up — their validator requires the tail to start with //, failing

in O(1) per hit.

Proof of Concept (confirmed, linkify-it 5.0.1, Node v24)

```js

const LinkifyIt = require('linkify-it');

const lf = new LinkifyIt();

lf.match('mailto:'.repeat(48000)); // ~336 KB of "mailto:mailto:…" -> seconds of blocked event loop

```

| input (same bytes) | 56 KB | 112 KB | 224 KB | 336 KB |

|---|---:|---:|---:|---:|

| mailto: contiguous | 97 ms | 357 ms | 1438 ms | 3272 ms |

| mailto: space-separated | 2 ms | 3 ms | 5 ms | 8 ms |

| http:// contiguous | 12 ms | 17 ms | 33 ms | 49 ms |

×~4 per 2× input ⇒ O(n²); equal-byte controls stay flat ⇒ algorithmic, not a GC/allocation artifact.

Real-world via markdown-it 14.x ({linkify:true}), md.render('mailto:'.repeat(n)): 219 KB ≈ ~5 s.

<img width="737" height="161" alt="image" src="https://github.com/user-attachments/assets/b5d390f3-68d0-4861-9c47-ad8aff0203d5" />

Impact

Reachable on arbitrary user text via the documented .test()/.match() API and through markdown-it's

linkifier — comment systems, chat, forums, wikis, note apps that render user markdown with linkify enabled.

A ~220 KB post hangs the event loop ~5 s; a few hundred KB → tens of seconds. Availability only.

Suggested remediation

Bound the email local-part per RFC 5321 (≤64) so per-hit work is O(1), and avoid the full-tail slice:

```js

// lib/re.mjs — cap the greedy run:

re.src_email_name = '[\\-;:&=\\+\\$,\\.a-zA-Z0-9_][\\-;:&=\\+\\$,\\"\\.a-zA-Z0-9_]{0,63}'

// index.mjs — prefer a sticky regex anchored at pos over text.slice(pos).

```

Affected / disclosure

All versions through 5.0.1 (latest); same code on master. cve-mcp/OSV report no known vulnerability for

linkify-it. Distinct from markdown-it's own *-run ReDoS (CVE-2026-2327, different package/path) and the

recent markdown-it DoS. Reported privately; happy to test a patch against the PoC.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Weakness class

CVE-2026-59887 is classified as CWE-407: Inefficient Algorithmic Complexity. Crafted input drives an algorithm into its worst case, so a small request costs disproportionate work.

Affected software

CVE-2026-59887 is recorded against 2 packages.

  • linkify-it
  • unknown

Timeline and source

Published on 21 July 2026 and last revised on 27 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
github.com (Web)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE CWE-407
Public Exploit ✅ No
Source NVD
Published 2026-07-21
Updated 2026-08-12
Modified 2026-07-27
Fix URL N/A

Affected Packages

Software From version Fixed in
linkify-it
unknown

Similar Threats

Site Security Check

Is linkify-it part of your stack?

CVE-2026-59887 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.