linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.
CVE-2026-48801
This high-severity CVE scores 7.5 under NVD CVSS v3. EPSS exploit probability: 0.4%, top 71% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
A fix is available — apply it.
- CVSS v3
- 7.5
- EG Score
- 7.5(medium)
- EG Risk
- 65(Attend)EG Risk 65/100SSVC: Attend
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity75% × 45%Exploitation40% × 40%Automatability100% × 15%Action: Remediate soon — notable exploitation risk. - EPSS PROB
- 0%
- EPSS %ILE
- 29%
- KEV
- Not listed
Published
June 26, 2026
Last Modified
August 6, 2026
Advisory Details (2)
Auto-updated Jul 14, 2026Quadratic algorithmic complexity in LinkifyIt#match scan loop · Advisory · markdown-it/linkify-it · GitHub
https://github.com/markdown-it/linkify-it/security/advisories/GHSA-22p9-wv53-3rq4commit 6be6d15e0641 (markdown-it/linkify-it)
Fix landed in markdown-it/linkify-it commit 6be6d15e0641 — awaiting tagged release
https://github.com/markdown-it/linkify-it/commit/6be6d15e0641bf1daeaa977d500cabc743166159Vendor Advisories for CVE-2026-48801(10)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2026:57590Red Hat Product SecurityHigh
Red Hat Security Advisory: rh-podman-desktop security, bug fix, and enhancement update
- RHSA-2026:56431Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.27 security, enhancement & bug fix update
- RHSA-2026:51038Red Hat Product SecurityHigh
Red Hat Security Advisory: OpenShift Container Platform 4.22.9 bug fix and security update
- RHSA-2026:51162Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.2 security update
- RHSA-2026:50850Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.1 security update
- RHSA-2026:49642Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Developer Hub 1.10.3 release.
- RHSA-2026:48126Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Developer Hub 1.10.3 Plugin Catalog GA plugins release.
- RHSA-2026:42815Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.2 security update
- +2 more
Patch Availability(9)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | rh-podman-desktop-0:1.1.2-1.el10_2 | 2026-08-20 | redhat |
| redhat | odf4/rook-ceph-rhel9-operator:1786706880 | 2026-08-18 | redhat |
| redhat | openshift4/ose-console-rhel9:1785910938 | 2026-08-11 | redhat |
| redhat | ansible-automation-platform/bootc-automation-portal-rhel9:1786006573 | 2026-08-06 | redhat |
| redhat | ansible-automation-platform/automation-portal:1785854226 | 2026-08-05 | redhat |
| redhat | rhdh/rhdh-hub-rhel9:1785411652 | 2026-08-03 | redhat |
| redhat | rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator:1785332694 | 2026-07-29 | redhat |
| redhat | ansible-automation-platform/automation-portal:1784622951 | 2026-07-21 | redhat |
| redhat | rust-main-1.97.0-1.1.hum1 | 2026-07-11 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
npm(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| linkify-it | — | 5.0.1 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 22× in last 7d / 106× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 128 total refreshes for this CVE.
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-25 02:17 UTCEG score recompute
- 2026-08-25 02:17 UTCVendor advisory
- 2026-08-24 13:28 UTCEG score recompute
- 2026-08-24 13:28 UTCVendor advisory
- 2026-08-24 00:38 UTCVendor advisory
- 2026-08-23 11:49 UTCEG score recompute
- 2026-08-23 11:49 UTCVendor advisory
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 23:00 UTCVendor advisory
- 2026-08-22 10:10 UTCEG score recompute
- 2026-08-22 10:10 UTCVendor advisory
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-21 21:12 UTCVendor advisory
- 2026-08-21 08:23 UTCEG score recompute
- 2026-08-21 08:23 UTCVendor advisory
- 2026-08-20 22:55 UTCEPSS rescore
- 2026-08-20 19:33 UTCVendor advisory
- 2026-08-20 06:44 UTCEG score recompute
- 2026-08-20 06:44 UTCVendor advisory
- 2026-08-19 17:04 UTCEPSS rescore
- 2026-08-19 12:37 UTCVendor advisory
- 2026-08-18 23:42 UTCEG score recompute
- 2026-08-18 23:42 UTCVendor advisory
- 2026-08-18 13:48 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-08-17 13:47 UTCEPSS rescore
- 2026-08-17 12:27 UTCVendor advisory
- 2026-08-16 23:22 UTCEG score recompute
- 2026-08-16 23:22 UTCVendor advisory
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 10:32 UTCEG score recompute
- 2026-08-16 10:32 UTCVendor advisory
- 2026-08-16 02:14 UTCEPSS rescore
- 2026-08-15 21:43 UTCVendor advisory
- 2026-08-15 08:52 UTCEG score recompute
- 2026-08-15 08:52 UTCVendor advisory
- 2026-08-15 01:30 UTCEPSS rescore
- 2026-08-14 20:02 UTCVendor advisory
- 2026-08-14 07:13 UTCEG score recompute
- 2026-08-14 07:13 UTCVendor advisory
- 2026-08-13 22:00 UTCEPSS rescore
- 2026-08-13 18:23 UTCVendor advisory
- 2026-08-13 04:30 UTCVendor advisory
- 2026-08-12 15:40 UTCEG score recompute
- 2026-08-12 15:40 UTCVendor advisory
- 2026-08-12 13:51 UTCEPSS rescore
- 2026-08-12 02:38 UTCVendor advisory
- 2026-08-11 13:49 UTCEG score recompute
- 2026-08-11 13:49 UTCVendor advisory
- 2026-08-11 00:59 UTCEG score recompute
- 2026-08-11 00:59 UTCVendor advisory
- 2026-08-11 00:00 UTCEPSS rescore
- 2026-08-10 12:10 UTCVendor advisory
- 2026-08-09 23:21 UTCEG score recompute
- 2026-08-09 23:21 UTCVendor advisory
- 2026-08-09 13:46 UTCEPSS rescore
- 2026-08-09 10:32 UTCVendor advisory
- 2026-08-08 21:43 UTCEG score recompute
- 2026-08-08 21:43 UTCVendor advisory
- 2026-08-08 16:37 UTCEPSS rescore
- 2026-08-08 08:54 UTCVendor advisory
- 2026-08-07 20:05 UTCEG score recompute
- 2026-08-07 20:05 UTCVendor advisory
- 2026-08-07 07:16 UTCEG score recompute▼ 1.20
- 2026-08-07 07:16 UTCVendor advisory
- 2026-08-06 18:35 UTCNVD updateCVSS v3 → 7.5
- 2026-08-06 18:26 UTCEG score recompute
- 2026-08-06 18:26 UTCVendor advisory
- 2026-08-06 13:47 UTCEPSS rescore
- 2026-08-06 05:37 UTCEG score recompute
- 2026-08-06 05:37 UTCVendor advisory
- 2026-08-05 19:17 UTCEPSS rescore
- 2026-08-05 16:48 UTCVendor advisory
- 2026-08-05 03:42 UTCEG score recompute
- 2026-08-05 03:42 UTCVendor advisory
- 2026-08-04 15:10 UTCEPSS rescore
- 2026-08-04 14:52 UTCEG score recompute
- 2026-08-04 14:52 UTCVendor advisory
- 2026-08-04 10:39 UTCEPSS rescore
- 2026-08-03 20:37 UTCEG score recompute
- 2026-08-03 20:37 UTCVendor advisory
- 2026-08-03 10:36 UTCEPSS rescore
- 2026-08-03 07:48 UTCVendor advisory
- 2026-08-02 18:21 UTCVendor advisory
- 2026-08-02 05:31 UTCEG score recompute
- 2026-08-02 05:31 UTCVendor advisory
- 2026-08-02 02:27 UTCEPSS rescore
- 2026-08-01 16:42 UTCEG score recompute
- 2026-08-01 16:42 UTCVendor advisory
- 2026-08-01 04:16 UTCEPSS rescore
- 2026-08-01 03:52 UTCVendor advisory
- 2026-07-31 15:01 UTCVendor advisory
- 2026-07-31 02:11 UTCEG score recompute
- 2026-07-31 02:11 UTCVendor advisory
- 2026-07-30 16:28 UTCEPSS rescore
- 2026-07-30 13:21 UTCEG score recompute
- 2026-07-30 13:21 UTCVendor advisory
- 2026-07-30 01:30 UTCEPSS rescore
- 2026-07-30 00:15 UTCVendor advisory
- 2026-07-29 09:13 UTCVendor advisory
Frequently asked(5)
What is CVE-2026-48801?
When was CVE-2026-48801 disclosed?
Is CVE-2026-48801 actively exploited?
What is the CVSS score of CVE-2026-48801?
How do I remediate CVE-2026-48801?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-48801
Is Your Infrastructure Affected by CVE-2026-48801?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.