CVE-2026-103043 Details
Description
anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.
A regular expression denial-of-service (ReDoS) vulnerability has been identified in the Anchorme library, specifically in versions through 3.0.8. The issue arises in the IPv6 host extraction regular expression, which is susceptible to catastrophic backtracking. Attackers can exploit this vulnerability by sending specially crafted input strings with repeated patterns, causing the regular expression engine to engage in exponential backtracking. This behavior blocks the Node.js event loop, effectively denying service to other requests.
Users are advised to limit the length of input text before it reaches the 'anchorme()' function, use the library in a worker thread or child process with a timeout, or replace Anchorme with alternative libraries like 'linkify-it' or 'autolinker', which do not have this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3 | CISA-ADP | ExploitTechnical Analysis |
| https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3 | [email protected] | ExploitTechnical Analysis |
| https://github.com/alexcorvi/anchorme.js | [email protected] | ProductVendor |
| https://github.com/alexcorvi/anchorme.js/blob/f3ae9850baa344f27b46bb149e9b891831d273b1/src/index.ts#L109 | [email protected] | |
| https://www.npmjs.com/package/anchorme | [email protected] | Permission RequiredProductVendor |
| https://www.vulncheck.com/advisories/anchorme-through-3.0.8-regular-expression-denial-of-service | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1333 | Inefficient Regular Expression Complexity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| anchorme | >= 3.0.2, <= 3.0.8 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion