Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59887

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.

A flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invoked, leading to excessive CPU consumption. This can result in a Denial of Service (DoS) for the affected system.

Отчет

This is an Important denial of service vulnerability in the linkify-it library. Systems processing untrusted user-supplied text containing specially crafted mailto: links may experience excessive CPU consumption due to a quadratic complexity issue in the mailto: schema validator, leading to temporary service disruption.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Under investigation
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Under investigation
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleUnder investigation
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorUnder investigation
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Under investigation
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel9Under investigation
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-pf5-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Affected
Red Hat Build of Podman Desktoprh-podman-desktop.gitNot affected
Red Hat Ceph Storage 9thriftUnder investigation

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2498146linkify-it: linkify-it: Denial of Service via crafted mailto: links

EPSS

Процентиль: 46%
0.00609
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.

CVSS3: 7.5
github
около 1 месяца назад

linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text

EPSS

Процентиль: 46%
0.00609
Низкий

7.5 High

CVSS3