CVE-2026-103043 PUBLISHED

anchorme through 3.0.8 Regular Expression Denial of Service

Assigner: VulnCheck
Reserved: 29.09.2026 Published: 29.09.2026 Updated: 29.09.2026

anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor alexcorvi
Product anchorme
Versions Default: unaffected
  • affected from 0 to 3.0.8 (incl.)

Credits

  • Mario Madersbacher finder

References

Problem Types

  • Inefficient Regular Expression Complexity CWE