CVE-2026-59887Disclosure(markdown-it / linkify-it)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch markdown-it linkify-it systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linkify-it

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
linkify-it

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-09: 1Mentions · 2026-07-11: 1PoC Mentioned / Linked · 2026-07-09: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-11: 107-0907-11
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-091
Disclosure1
2026-07-111
Patch1
Full discourse2 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-59887 (CVSS 7.5) linkify-it library vulnerable to O(n^2) DoS via crafted mailto: links. Affects versions <5.0.2. ✅ Update to v5.0.2 immediately #CVE #Vulnerability #PatchNow https://t.co/nI2mHuYQPl

    Post summary

    The tweet announces a high‑severity CVE‑2026‑59887 in the linkify‑it library that allows an O(n²) Denial‑of‑Service via crafted mailto links, and it advises an immediate update to v5.0.2.

    0000043
    71 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-59887 - #ReDoS in linkify-it library. Malicious mailto: inputs cause O(n^2) CPU consumption. #CVSS 7.5. No patch available. Update to 5.0.2. #CVEAlert #devsecops #devops #sysadmin #linux #python #git #github #gitlab #100daysofdevelopment #JavaScript #infosec https://www.valtersit.com/cve/CVE-2026-59887/

    Post summary

    A new ReDoS vulnerability (CVE‑2026‑59887) in the linkify‑it JavaScript library causes quadratic CPU consumption from crafted mailto inputs; no patch yet, but update to 5.0.2 is recommended. Technical specifics and a reference link are provided.

    0000064
    974 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmarkdown-itlinkify-it-node.js-

Explore more