Back

HIGH

linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop

Published Jul 14, 2026

Description

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.

Affected products

Remediation

Red Hat statement

This Moderate impact flaw in linkify-it, a link recognition library, can lead to a denial of service in Red Hat products. The vulnerability arises from an O(N²) algorithmic complexity when processing untrusted Markdown with numerous fuzzy links or emails, potentially causing excessive CPU consumption and worker-process unavailability. This risk is present in services that synchronously render untrusted Markdown with the linkify feature enabled.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 14, 2026
Updated Jul 15, 2026
Reserved May 22, 2026
CISA Vulnrichment
Updated Jul 15, 2026
NVD
Status Analyzed
Modified Aug 6, 2026
Red Hat
Severity Moderate
Public date Jul 14, 2026
ENISA EUVD
Assigner GitHub_M
Published Jul 14, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2026-44454 GHSA-22P9-WV53-3RQ4