{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-59887",
        "tracking": {
            "current_release_date": "2026-08-20T00:53:38.715403Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-59887",
            "initial_release_date": "2026-07-08T17:07:21.329568Z",
            "revision_history": [
                {
                    "date": "2026-07-08T17:07:21.329568Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-07-08T17:07:25.013741Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-07-08T17:28:04.070421Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-07-08T17:28:06.752387Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-09T06:37:43.445992Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (29).| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-07-09T16:21:59.983694Z",
                    "number": "6",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-07-09T16:37:21.008640Z",
                    "number": "7",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-07-09T16:37:24.272409Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-21T19:59:46.709780Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-07-21T19:59:54.745252Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-22T00:23:50.192302Z",
                    "number": "11",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-08-19T12:06:59.673118Z",
                    "number": "12",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (11).| References created (3)."
                },
                {
                    "date": "2026-08-19T12:07:01.872961Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T15:16:43.346002Z",
                    "number": "14",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                }
            ],
            "status": "interim",
            "version": "14"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.22",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.22",
                                    "product_id": "CSAFPID-9012403"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <12.1.10",
                                "product": {
                                    "name": "vers:unknown/data center lts <12.1.10",
                                    "product_id": "CSAFPID-9012404"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Bamboo"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center <10.4.2",
                                "product": {
                                    "name": "vers:unknown/data center <10.4.2",
                                    "product_id": "CSAFPID-9012406"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.6",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.6",
                                    "product_id": "CSAFPID-9012408"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <9.4.23",
                                "product": {
                                    "name": "vers:unknown/data center lts <9.4.23",
                                    "product_id": "CSAFPID-9012407"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Bitbucket"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.15",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.15",
                                    "product_id": "CSAFPID-9012410"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <9.2.23",
                                "product": {
                                    "name": "vers:unknown/data center lts <9.2.23",
                                    "product_id": "CSAFPID-9012409"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Confluence"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.13",
                                "product": {
                                    "name": "vers:unknown/<4.9.13",
                                    "product_id": "CSAFPID-9012413"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Crucible"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.13",
                                "product": {
                                    "name": "vers:unknown/<4.9.13",
                                    "product_id": "CSAFPID-9012411"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Fisheye"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.3.24",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.3.24",
                                    "product_id": "CSAFPID-9012405"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <11.3.10",
                                "product": {
                                    "name": "vers:unknown/data center lts <11.3.10",
                                    "product_id": "CSAFPID-9012414"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Jira"
                    }
                ],
                "category": "vendor",
                "name": "Atlassian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.1.0",
                                "product": {
                                    "name": "vers:unknown/0.1.0",
                                    "product_id": "CSAFPID-8581653"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.1.1",
                                "product": {
                                    "name": "vers:unknown/0.1.1",
                                    "product_id": "CSAFPID-8581652"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.1.2",
                                "product": {
                                    "name": "vers:unknown/0.1.2",
                                    "product_id": "CSAFPID-8581651"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.1.3",
                                "product": {
                                    "name": "vers:unknown/0.1.3",
                                    "product_id": "CSAFPID-8581650"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.1.4",
                                "product": {
                                    "name": "vers:unknown/0.1.4",
                                    "product_id": "CSAFPID-8581649"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/0.1.5",
                                "product": {
                                    "name": "vers:unknown/0.1.5",
                                    "product_id": "CSAFPID-8581648"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.0",
                                "product": {
                                    "name": "vers:unknown/1.0.0",
                                    "product_id": "CSAFPID-8581647"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.1",
                                "product": {
                                    "name": "vers:unknown/1.0.1",
                                    "product_id": "CSAFPID-8581646"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.0",
                                "product": {
                                    "name": "vers:unknown/1.1.0",
                                    "product_id": "CSAFPID-8581645"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.1.1",
                                "product": {
                                    "name": "vers:unknown/1.1.1",
                                    "product_id": "CSAFPID-8581644"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.0",
                                "product": {
                                    "name": "vers:unknown/1.2.0",
                                    "product_id": "CSAFPID-8581643"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.1",
                                "product": {
                                    "name": "vers:unknown/1.2.1",
                                    "product_id": "CSAFPID-8581642"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.2",
                                "product": {
                                    "name": "vers:unknown/1.2.2",
                                    "product_id": "CSAFPID-8581641"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.3",
                                "product": {
                                    "name": "vers:unknown/1.2.3",
                                    "product_id": "CSAFPID-8581640"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.2.4",
                                "product": {
                                    "name": "vers:unknown/1.2.4",
                                    "product_id": "CSAFPID-8581639"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.0",
                                "product": {
                                    "name": "vers:unknown/2.0.0",
                                    "product_id": "CSAFPID-8581638"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.1",
                                "product": {
                                    "name": "vers:unknown/2.0.1",
                                    "product_id": "CSAFPID-8581637"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.2",
                                "product": {
                                    "name": "vers:unknown/2.0.2",
                                    "product_id": "CSAFPID-8581636"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0.3",
                                "product": {
                                    "name": "vers:unknown/2.0.3",
                                    "product_id": "CSAFPID-8581635"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1.0",
                                "product": {
                                    "name": "vers:unknown/2.1.0",
                                    "product_id": "CSAFPID-8581634"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.2.0",
                                "product": {
                                    "name": "vers:unknown/2.2.0",
                                    "product_id": "CSAFPID-8581633"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.0",
                                "product": {
                                    "name": "vers:unknown/3.0.0",
                                    "product_id": "CSAFPID-8581632"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.1",
                                "product": {
                                    "name": "vers:unknown/3.0.1",
                                    "product_id": "CSAFPID-8581631"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.2",
                                "product": {
                                    "name": "vers:unknown/3.0.2",
                                    "product_id": "CSAFPID-8581630"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.3",
                                "product": {
                                    "name": "vers:unknown/3.0.3",
                                    "product_id": "CSAFPID-8581629"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.0.0",
                                "product": {
                                    "name": "vers:unknown/4.0.0",
                                    "product_id": "CSAFPID-8581628"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/4.0.1",
                                "product": {
                                    "name": "vers:unknown/4.0.1",
                                    "product_id": "CSAFPID-8581627"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.0",
                                "product": {
                                    "name": "vers:unknown/5.0.0",
                                    "product_id": "CSAFPID-8581626"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.0.1",
                                "product": {
                                    "name": "vers:unknown/5.0.1",
                                    "product_id": "CSAFPID-8581625"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<5.0.2",
                                "product": {
                                    "name": "vers:unknown/<5.0.2",
                                    "product_id": "CSAFPID-8575052"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<5.0.2",
                                "product": {
                                    "name": "vers:unknown/>=0|<5.0.2",
                                    "product_id": "CSAFPID-8873361"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "linkify-it"
                    }
                ],
                "category": "vendor",
                "name": "markdown-it"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-59887",
            "cwe": {
                "id": "CWE-407",
                "name": "Inefficient Algorithmic Complexity"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/59xxx/CVE-2026-59887.json"
                },
                {
                    "category": "description",
                    "text": "linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-59887"
                },
                {
                    "category": "description",
                    "text": "linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used by .test() and .match() can be invoked at every mailto: occurrence and scan the remaining input through src_email_name in lib/re.mjs, causing O(n^2) CPU consumption on crafted user text. This issue is fixed in version 5.0.2.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-59887.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "### Summary\n`linkify-it`'s schema-scan loop (`.test()` / `.match()`, the documented public API) invokes the `mailto:`\nschema validator at **every** `mailto:` occurrence in the input text. For each occurrence the validator does\n`text.slice(pos)` (an O(n) copy) and runs an email regex whose local-part class `src_email_name` greedily\nscans the **entire remaining tail** (O(n)) before failing. With N `mailto:` occurrences that is\n**N × O(n) = O(n²)**. Because linkify-it runs on arbitrary user text (markdown-it feeds it whole documents\nwhen `linkify:true`), an unauthenticated attacker can block the single-threaded event loop for many seconds\nwith a small input. No length bound (unlike an HTTP header).\n\n### Root cause — `index.mjs` + `lib/re.mjs`\n```js\n// index.mjs (mailto validator) — runs at every \"mailto:\" hit\n'mailto:': { validate: function (text, pos, self) {\n  const tail = text.slice(pos)                                  // O(n) copy per hit\n  if (!self.re.mailto) self.re.mailto = new RegExp('^' + self.re.src_email_name + '@' + self.re.src_host_strict, 'i')\n  if (self.re.mailto.test(tail)) { ... }                        // scans the whole O(n) tail\n  return 0\n}}\n// lib/re.mjs:91-93 — every char of \"mailto:\" (incl. ':','-',';') is in this class:\nre.src_email_name = '[\\\\-;:&=\\\\+\\\\$,\\\\.a-zA-Z0-9_][\\\\-;:&=\\\\+\\\\$,\\\\\"\\\\.a-zA-Z0-9_]*'\n```\nThe `while ((m = re.exec(text)) !== null) { …testSchemaAt… }` scan loop calls the validator at each\n`mailto:` hit; `src_email_name` greedily consumes the whole tail (all chars are in its class) then fails for\nlack of `@`. `http:`/`https:` do NOT blow up — their validator requires the tail to start with `//`, failing\nin O(1) per hit.\n\n### Proof of Concept (confirmed, linkify-it 5.0.1, Node v24)\n```js\nconst LinkifyIt = require('linkify-it');\nconst lf = new LinkifyIt();\nlf.match('mailto:'.repeat(48000));   // ~336 KB of \"mailto:mailto:…\" -> seconds of blocked event loop\n```\n| input (same bytes) | 56 KB | 112 KB | 224 KB | 336 KB |\n|---|---:|---:|---:|---:|\n| **`mailto:` contiguous** | 97 ms | 357 ms | 1438 ms | 3272 ms |\n| `mailto:` space-separated | 2 ms | 3 ms | 5 ms | 8 ms |\n| `http://` contiguous | 12 ms | 17 ms | 33 ms | 49 ms |\n\n×~4 per 2× input ⇒ O(n²); equal-byte controls stay flat ⇒ algorithmic, not a GC/allocation artifact.\nReal-world via markdown-it 14.x (`{linkify:true}`), `md.render('mailto:'.repeat(n))`: 219 KB ≈ ~5 s.\n<img width=\"737\" height=\"161\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b5d390f3-68d0-4861-9c47-ad8aff0203d5\" />\n\n### Impact\nReachable on arbitrary user text via the documented `.test()`/`.match()` API and through markdown-it's\nlinkifier — comment systems, chat, forums, wikis, note apps that render user markdown with linkify enabled.\nA ~220 KB post hangs the event loop ~5 s; a few hundred KB → tens of seconds. Availability only.\n\n### Suggested remediation\nBound the email local-part per RFC 5321 (≤64) so per-hit work is O(1), and avoid the full-tail slice:\n```js\n// lib/re.mjs — cap the greedy run:\nre.src_email_name = '[\\\\-;:&=\\\\+\\\\$,\\\\.a-zA-Z0-9_][\\\\-;:&=\\\\+\\\\$,\\\\\"\\\\.a-zA-Z0-9_]{0,63}'\n// index.mjs — prefer a sticky regex anchored at `pos` over text.slice(pos).\n```\n\n### Affected / disclosure\nAll versions through 5.0.1 (latest); same code on `master`. cve-mcp/OSV report no known vulnerability for\nlinkify-it. Distinct from markdown-it's own `*`-run ReDoS (CVE-2026-2327, different package/path) and the\nrecent markdown-it DoS. Reported privately; happy to test a patch against the PoC.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-v245-v573-v5vm.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "### Summary\n`linkify-it`'s schema-scan loop (`.test()` / `.match()`, the documented public API) invokes the `mailto:`\nschema validator at **every** `mailto:` occurrence in the input text. For each occurrence the validator does\n`text.slice(pos)` (an O(n) copy) and runs an email regex whose local-part class `src_email_name` greedily\nscans the **entire remaining tail** (O(n)) before failing. With N `mailto:` occurrences that is\n**N × O(n) = O(n²)**. Because linkify-it runs on arbitrary user text (markdown-it feeds it whole documents\nwhen `linkify:true`), an unauthenticated attacker can block the single-threaded event loop for many seconds\nwith a small input. No length bound (unlike an HTTP header).\n\n### Root cause — `index.mjs` + `lib/re.mjs`\n```js\n// index.mjs (mailto validator) — runs at every \"mailto:\" hit\n'mailto:': { validate: function (text, pos, self) {\n  const tail = text.slice(pos)                                  // O(n) copy per hit\n  if (!self.re.mailto) self.re.mailto = new RegExp('^' + self.re.src_email_name + '@' + self.re.src_host_strict, 'i')\n  if (self.re.mailto.test(tail)) { ... }                        // scans the whole O(n) tail\n  return 0\n}}\n// lib/re.mjs:91-93 — every char of \"mailto:\" (incl. ':','-',';') is in this class:\nre.src_email_name = '[\\\\-;:&=\\\\+\\\\$,\\\\.a-zA-Z0-9_][\\\\-;:&=\\\\+\\\\$,\\\\\"\\\\.a-zA-Z0-9_]*'\n```\nThe `while ((m = re.exec(text)) !== null) { …testSchemaAt… }` scan loop calls the validator at each\n`mailto:` hit; `src_email_name` greedily consumes the whole tail (all chars are in its class) then fails for\nlack of `@`. `http:`/`https:` do NOT blow up — their validator requires the tail to start with `//`, failing\nin O(1) per hit.\n\n### Proof of Concept (confirmed, linkify-it 5.0.1, Node v24)\n```js\nconst LinkifyIt = require('linkify-it');\nconst lf = new LinkifyIt();\nlf.match('mailto:'.repeat(48000));   // ~336 KB of \"mailto:mailto:…\" -> seconds of blocked event loop\n```\n| input (same bytes) | 56 KB | 112 KB | 224 KB | 336 KB |\n|---|---:|---:|---:|---:|\n| **`mailto:` contiguous** | 97 ms | 357 ms | 1438 ms | 3272 ms |\n| `mailto:` space-separated | 2 ms | 3 ms | 5 ms | 8 ms |\n| `http://` contiguous | 12 ms | 17 ms | 33 ms | 49 ms |\n\n×~4 per 2× input ⇒ O(n²); equal-byte controls stay flat ⇒ algorithmic, not a GC/allocation artifact.\nReal-world via markdown-it 14.x (`{linkify:true}`), `md.render('mailto:'.repeat(n))`: 219 KB ≈ ~5 s.\n<img width=\"737\" height=\"161\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b5d390f3-68d0-4861-9c47-ad8aff0203d5\" />\n\n### Impact\nReachable on arbitrary user text via the documented `.test()`/`.match()` API and through markdown-it's\nlinkifier — comment systems, chat, forums, wikis, note apps that render user markdown with linkify enabled.\nA ~220 KB post hangs the event loop ~5 s; a few hundred KB → tens of seconds. Availability only.\n\n### Suggested remediation\nBound the email local-part per RFC 5321 (≤64) so per-hit work is O(1), and avoid the full-tail slice:\n```js\n// lib/re.mjs — cap the greedy run:\nre.src_email_name = '[\\\\-;:&=\\\\+\\\\$,\\\\.a-zA-Z0-9_][\\\\-;:&=\\\\+\\\\$,\\\\\"\\\\.a-zA-Z0-9_]{0,63}'\n// index.mjs — prefer a sticky regex anchored at `pos` over text.slice(pos).\n```\n\n### Affected / disclosure\nAll versions through 5.0.1 (latest); same code on `master`. cve-mcp/OSV report no known vulnerability for\nlinkify-it. Distinct from markdown-it's own `*`-run ReDoS (CVE-2026-2327, different package/path) and the\nrecent markdown-it DoS. Reported privately; happy to test a patch against the PoC.",
                    "title": "github - https://api.github.com/advisories/GHSA-v245-v573-v5vm"
                },
                {
                    "category": "other",
                    "text": "0.00342",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "5.1",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde, Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top increasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-8575052",
                    "CSAFPID-8581625",
                    "CSAFPID-8581626",
                    "CSAFPID-8581627",
                    "CSAFPID-8581628",
                    "CSAFPID-8581629",
                    "CSAFPID-8581630",
                    "CSAFPID-8581631",
                    "CSAFPID-8581632",
                    "CSAFPID-8581633",
                    "CSAFPID-8581634",
                    "CSAFPID-8581635",
                    "CSAFPID-8581636",
                    "CSAFPID-8581637",
                    "CSAFPID-8581638",
                    "CSAFPID-8581639",
                    "CSAFPID-8581640",
                    "CSAFPID-8581641",
                    "CSAFPID-8581642",
                    "CSAFPID-8581643",
                    "CSAFPID-8581644",
                    "CSAFPID-8581645",
                    "CSAFPID-8581646",
                    "CSAFPID-8581647",
                    "CSAFPID-8581648",
                    "CSAFPID-8581649",
                    "CSAFPID-8581650",
                    "CSAFPID-8581651",
                    "CSAFPID-8581652",
                    "CSAFPID-8581653",
                    "CSAFPID-8873361",
                    "CSAFPID-9012403",
                    "CSAFPID-9012404",
                    "CSAFPID-9012405",
                    "CSAFPID-9012406",
                    "CSAFPID-9012407",
                    "CSAFPID-9012408",
                    "CSAFPID-9012409",
                    "CSAFPID-9012410",
                    "CSAFPID-9012411",
                    "CSAFPID-9012413",
                    "CSAFPID-9012414"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/59xxx/CVE-2026-59887.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-59887"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-59887.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-v245-v573-v5vm.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-v245-v573-v5vm"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2923.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=10000"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/markdown-it/linkify-it/security/advisories/GHSA-v245-v573-v5vm"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/markdown-it/linkify-it/commit/105e5d77f7d119871d2b2d86ed208568eb3e7ffe"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/markdown-it/linkify-it/releases/tag/5.0.2"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59887.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59887"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-v245-v573-v5vm"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2923.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2923"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://confluence.atlassian.com/security/security-bulletin-august-18-2026-1821999768.html"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-8575052",
                        "CSAFPID-8581625",
                        "CSAFPID-8581626",
                        "CSAFPID-8581627",
                        "CSAFPID-8581628",
                        "CSAFPID-8581629",
                        "CSAFPID-8581630",
                        "CSAFPID-8581631",
                        "CSAFPID-8581632",
                        "CSAFPID-8581633",
                        "CSAFPID-8581634",
                        "CSAFPID-8581635",
                        "CSAFPID-8581636",
                        "CSAFPID-8581637",
                        "CSAFPID-8581638",
                        "CSAFPID-8581639",
                        "CSAFPID-8581640",
                        "CSAFPID-8581641",
                        "CSAFPID-8581642",
                        "CSAFPID-8581643",
                        "CSAFPID-8581644",
                        "CSAFPID-8581645",
                        "CSAFPID-8581646",
                        "CSAFPID-8581647",
                        "CSAFPID-8581648",
                        "CSAFPID-8581649",
                        "CSAFPID-8581650",
                        "CSAFPID-8581651",
                        "CSAFPID-8581652",
                        "CSAFPID-8581653",
                        "CSAFPID-8873361",
                        "CSAFPID-9012403",
                        "CSAFPID-9012404",
                        "CSAFPID-9012405",
                        "CSAFPID-9012406",
                        "CSAFPID-9012407",
                        "CSAFPID-9012408",
                        "CSAFPID-9012409",
                        "CSAFPID-9012410",
                        "CSAFPID-9012411",
                        "CSAFPID-9012413",
                        "CSAFPID-9012414"
                    ]
                }
            ],
            "title": "CVE-2026-59887"
        }
    ]
}