{"id":"CVE-2026-59887","title":"linkify-it: linkify-it: Denial of Service via crafted mailto: links (CVE-2026-59887)","summary":"A flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invok…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-1333","CWE-407"],"vendor":"Red Hat","product":"Red Hat OpenShift Dev Spaces 3.30","affected":["migration_toolkit_for_virtualization","node_healthcheck_operator","openshift_pipelines","ceph_storage 9","developer_hub","openshift_ai_rhoai","openshift_container_platform 4","openshift_data_foundation 4","openshift_dev_spaces","self_service_automation_portal 2","openshift_dev_spaces 3.30"],"patched":["openshift_dev_spaces 3.30"],"published":"2026-07-08","updated":"2026-09-25","sourceUpdated":"2026-09-25T04:25:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59887.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59887.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59887"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498146"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59887"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59887"},{"url":"https://github.com/markdown-it/linkify-it/commit/105e5d77f7d119871d2b2d86ed208568eb3e7ffe"},{"url":"https://github.com/markdown-it/linkify-it/releases/tag/5.0.2"},{"url":"https://github.com/markdown-it/linkify-it/security/advisories/GHSA-v245-v573-v5vm"},{"url":"https://access.redhat.com/errata/RHSA-2026:68754"},{"url":"https://github.com/advisories/GHSA-v245-v573-v5vm"}],"tags":["csaf","vex","red-hat","ghsa","npm"],"epss":0.00644,"epssPercentile":0.48603,"aliases":["GHSA-v245-v573-v5vm"],"ecosystem":"npm","ingestedAt":"2026-07-21T19:53:40.199Z","slug":"CVE-2026-59887","body":"## Overview\n\nA flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invoked, leading to excessive CPU consumption. This can result in a Denial of Service (DoS) for the affected system.\n\n## Vendor advisories\n\n- **RHSA-2026:68754** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68754)\n- **Red Hat VEX** · Important · affected: Migration Toolkit for Virtualization, Node HealthCheck Operator, OpenShift Pipelines, Red Hat Ceph Storage 9, Red Hat Developer Hub, Red Hat OpenShift AI (RHOAI), … · no fix planned: Red Hat Ceph Storage 9, Migration Toolkit for Virtualization, Node HealthCheck Operator, OpenShift Pipelines, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59887.json)\n\n**linkify-it: linkify-it: Denial of Service via crafted mailto: links** — rated Important by Red Hat. Released 2026-07-08, updated 2026-09-25.\n\nAffected:\n\n- Migration Toolkit for Virtualization\n- Node HealthCheck Operator\n- OpenShift Pipelines\n- Red Hat Ceph Storage 9\n- Red Hat Developer Hub\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n- Red Hat OpenShift Dev Spaces\n- Self-service automation portal 2\n\nFixed:\n\n- Red Hat OpenShift Dev Spaces 3.30\n\nNo fix planned:\n\n- Red Hat Ceph Storage 9\n- Migration Toolkit for Virtualization\n- Node HealthCheck Operator\n- OpenShift Pipelines\n- Red Hat Developer Hub\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat Openshift Data Foundation 4\n- Red Hat OpenShift Dev Spaces\n\nNot affected:\n\n- Red Hat OpenShift Dev Spaces 3.30\n- Red Hat Build of Podman Desktop\n- Red Hat Developer Hub\n- Red Hat Hardened Images\n- Red Hat OpenShift Virtualization 4\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata  relevant to your system have been applied. \nFor details on how to apply this update, refer to: \nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68754\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-59887)\n\nAffected packages:\n\n- `linkify-it <= 5.0.1`\n\nPatched in:\n\n- `linkify-it 5.0.2`\n\nSource: https://github.com/advisories/GHSA-v245-v573-v5vm","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}