CVE-2026-103043
HIGH
8,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.
1333
Inefficient Regular Expression Complexity
DraftCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Applicable Platforms
All platforms may be affected
https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3
https://github.com/alexcorvi/anchorme.js
https://github.com/alexcorvi/anchorme.js/blob/f3ae9850baa344f27b46bb149e9b89183…
https://www.npmjs.com/package/anchorme
https://www.vulncheck.com/advisories/anchorme-through-3.0.8-regular-expression-…