[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-48801":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T17:19:26.604Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":24,"aliases":25,"duplicate_of":9,"upstream":27,"downstream":28,"duplicates":33,"related":34,"reserved_at":9,"published_at":37,"modified_at":38,"state":39,"summary":40,"references_raw":47,"kevs":65,"epss":9,"epss_history":66,"metrics":67,"affected":73},"CVE-2026-48801","linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails. Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-1333","Inefficient Regular Expression Complexity","The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.","weakness","Draft","Base","High",[20],{"id":21,"name":22,"techniques":23},"CAPEC-492","Regular Expression Exponential Blowup",[],[],[26],"GHSA-22p9-wv53-3rq4",[],[29,31],{"_key":30},"RHSA-2026:38187",{"_key":32},"UBUNTU-CVE-2026-48801",[],[35],{"_key":36},"CGA-482V-4W6M-PXJW","2026-07-14T20:03:56.430Z","2026-07-15T12:56:15.250Z","PUBLISHED",{"cisa_kev":41,"cisa_ransomware":41,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":42,"severity_score":43,"severity_version":44,"severity_source":45,"severity_vector":46,"severity_status":39},false,"high",8.7,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",[48,55,60],{"url":49,"sources":50,"tags":52},"https://github.com/markdown-it/linkify-it/security/advisories/GHSA-22p9-wv53-3rq4",[51,45],"osv_npm",[53,54],"WEB","X Refsource CONFIRM",{"url":56,"sources":57,"tags":58},"https://github.com/markdown-it/linkify-it",[51],[59],"PACKAGE",{"url":61,"sources":62,"tags":63},"https://github.com/markdown-it/linkify-it/commit/6be6d15e0641bf1daeaa977d500cabc743166159",[45],[64],"X Refsource MISC",[],[],[68,70],{"source":51,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":69},{"baseScore":43,"baseSeverity":9,"vectorString":46,"impactScore":9,"exploitabilityScore":9},{"source":45,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":71},{"baseScore":43,"baseSeverity":72,"vectorString":46,"impactScore":9,"exploitabilityScore":9},"HIGH",[74,84],{"ecosystem":9,"name":75,"vendor":76,"product":75,"cpe_part":77,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":78},"linkify-it","markdown-it","a",[79],{"version":80,"is_range":81,"range_type":45,"version_start":9,"version_start_type":9,"version_end":82,"version_end_type":83,"fixed_in":9},"\u003C 5.0.1",true,"5.0.1","excluding",{"ecosystem":85,"name":75,"vendor":85,"product":75,"cpe_part":9,"purl_type":86,"purl_namespace":9,"purl_name":75,"source":9,"versions":87},"Npm","npm",[88],{"version":89,"is_range":81,"range_type":90,"version_start":9,"version_start_type":9,"version_end":82,"version_end_type":83,"fixed_in":9},"lt5_0_1","semver"]