---
id: CVE-2026-59887
title: >-
  linkify-it: linkify-it: Denial of Service via crafted mailto: links
  (CVE-2026-59887)
summary: >-
  A flaw was found in linkify-it, a library for recognizing links. A remote
  attacker could exploit this vulnerability by providing specially crafted user
  text. The mailto: schema validator, when processing this input, can be
  repeatedly invok…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-1333
  - CWE-407
vendor: Red Hat
product: Red Hat OpenShift Dev Spaces 3.30
affected:
  - migration_toolkit_for_virtualization
  - node_healthcheck_operator
  - openshift_pipelines
  - ceph_storage 9
  - developer_hub
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_data_foundation 4
  - openshift_dev_spaces
  - self_service_automation_portal 2
  - openshift_dev_spaces 3.30
patched:
  - openshift_dev_spaces 3.30
published: '2026-07-08'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T04:25:38+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59887.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59887.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59887'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2498146'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59887'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59887'
  - url: >-
      https://github.com/markdown-it/linkify-it/commit/105e5d77f7d119871d2b2d86ed208568eb3e7ffe
  - url: 'https://github.com/markdown-it/linkify-it/releases/tag/5.0.2'
  - url: >-
      https://github.com/markdown-it/linkify-it/security/advisories/GHSA-v245-v573-v5vm
  - url: 'https://access.redhat.com/errata/RHSA-2026:68754'
  - url: 'https://github.com/advisories/GHSA-v245-v573-v5vm'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
epss: 0.00644
epssPercentile: 0.48675
aliases:
  - GHSA-v245-v573-v5vm
ecosystem: npm
ingestedAt: '2026-07-21T19:53:40.199Z'
---

## Overview

A flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invoked, leading to excessive CPU consumption. This can result in a Denial of Service (DoS) for the affected system.

## Vendor advisories

- **RHSA-2026:68754** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces 3.30 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68754)
- **Red Hat VEX** · Important · affected: Migration Toolkit for Virtualization, Node HealthCheck Operator, OpenShift Pipelines, Red Hat Ceph Storage 9, Red Hat Developer Hub, Red Hat OpenShift AI (RHOAI), … · no fix planned: Red Hat Ceph Storage 9, Migration Toolkit for Virtualization, Node HealthCheck Operator, OpenShift Pipelines, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59887.json)

**linkify-it: linkify-it: Denial of Service via crafted mailto: links** — rated Important by Red Hat. Released 2026-07-08, updated 2026-09-25.

Affected:

- Migration Toolkit for Virtualization
- Node HealthCheck Operator
- OpenShift Pipelines
- Red Hat Ceph Storage 9
- Red Hat Developer Hub
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift Dev Spaces
- Self-service automation portal 2

Fixed:

- Red Hat OpenShift Dev Spaces 3.30

No fix planned:

- Red Hat Ceph Storage 9
- Migration Toolkit for Virtualization
- Node HealthCheck Operator
- OpenShift Pipelines
- Red Hat Developer Hub
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4
- Red Hat OpenShift Dev Spaces

Not affected:

- Red Hat OpenShift Dev Spaces 3.30
- Red Hat Build of Podman Desktop
- Red Hat Developer Hub
- Red Hat Hardened Images
- Red Hat OpenShift Virtualization 4

## Remediation

Before applying this update, make sure all previously released errata  relevant to your system have been applied. 
For details on how to apply this update, refer to: 
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:68754

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-59887)

Affected packages:

- `linkify-it <= 5.0.1`

Patched in:

- `linkify-it 5.0.2`

Source: https://github.com/advisories/GHSA-v245-v573-v5vm
