---
id: CVE-2026-103043
title: >-
  anchorme through 3.0.8 contains a regular expression denial of service
  vulnerability in the IPv6 host extraction regex due to catastrophic
  backtracking
summary: >-
  anchorme through 3.0.8 contains a regular expression denial of service
  vulnerability in the IPv6 host extraction regex due to catastrophic
  backtracking. Attackers can supply specially crafted input strings with
  repeated patterns to cause…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-1333
vendor: alexcorvi
product: anchorme
affected:
  - anchorme <= 3.0.8
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T23:17:22.023'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103043'
references:
  - url: 'https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/alexcorvi/anchorme.js'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/alexcorvi/anchorme.js/blob/f3ae9850baa344f27b46bb149e9b891831d273b1/src/index.ts#L109
    label: disclosure@vulncheck.com
  - url: 'https://www.npmjs.com/package/anchorme'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/anchorme-through-3.0.8-regular-expression-denial-of-service
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T23:52:50.535Z'
---

## Overview

anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
