Inefficient Algorithmic Complexity in linkify-it - CVE-2026-59887
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the mailto: schema validator scan loop when processing user-supplied text containing repeated mailto: sequences. A remote attacker can send specially crafted input to cause a denial of service.
The issue is reachable through the documented .test() and .match() API and through markdown rendering with linkification enabled.
Affected software
Confluence Data Center
Fedora
python-linkify-it-py
How to mitigate CVE-2026-59887
Confluence Data Center - addressed in versions 9.2.23, 10.2.15
python-linkify-it-py - update to 2.1.1-1.fc44