Skip to content
VulniPulse
High7.5Vendor: MediumRed Hat Linux

High [CVE-2026-48801] Denial of Service via algorithmic complexity vulnerability

This high-severity Red Hat Linux advisory covers CVE-2026-48801 affecting Red Hat Enterprise Linux 10, Red Hat Ansible Automation Platform 2.1, Red Hat Ansible Automation Platform 2.2.

CVE-2026-48801 Published Jul 14, 2026Updated by vendor Jul 14, 2026
Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices input and re-runs unanchored regex searches on progressively shorter tails.

Any service that synchronously renders untrusted Markdown with linkify:true on a request hot path can inherit a worker-process denial of service triggerable by a tens-of-KB request body. This issue is fixed in version 5.0.1.

This can be exploited by a remote attacker sending a specially crafted request body, leading to a worker-process denial of service (DoS) due to excessive CPU usage when synchronously rendering untrusted Markdown with linkify enabled. This Moderate impact flaw in linkify-it, a link recognition library, can lead to a denial of service in Red Hat products.

The vulnerability arises from an O(N²) algorithmic complexity when processing untrusted Markdown with numerous fuzzy links or emails, potentially causing excessive CPU consumption and worker-process unavailability. This risk is present in services that synchronously render untrusted Markdown with the linkify feature enabled.

Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-1333.

Affected versions
  • < 5.0.1

Official advisory · high-confidence parse· fetched 3 days ago·verify at source

Fixed versions
  • 5.0.1
  • rh-podman-desktop-0:1.1.2-1.el10_2
  • ansible-automation-platform/automation-portal:1785854226
  • ansible-automation-platform/automation-portal:1784622951
  • ansible-automation-platform/bootc-automation-portal-rhel9:1786006573
  • rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1785332825
  • rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki:1785332668
  • rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator:1785332694
  • rhdh/rhdh-hub-rhel9:1785411652
  • rust-main-1.97.0-1.1.hum1
  • rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:1787121387
  • openshift4/ose-console-rhel9:1787737695
  • openshift4/ose-monitoring-plugin-rhel9:1787736396
  • openshift4/ose-console-rhel9:1787590523
  • openshift4/ose-monitoring-plugin-rhel9:1787590390
  • openshift4/ose-console-rhel9:1785910938
  • openshift4/ose-monitoring-plugin-rhel9:1787730804
  • openshift4/ose-networking-console-plugin-rhel9:1787745534
  • odf4/cephcsi-rhel9:1786705347
  • odf4/cephcsi-rhel9-operator:1786706101
  • odf4/mcg-core-rhel9:1786705558
  • odf4/mcg-rhel9-operator:1786705646
  • odf4/ocs-client-console-rhel9:1786706138
  • odf4/ocs-client-rhel9-operator:1786705741
  • odf4/ocs-metrics-exporter-rhel9:1786705777
  • odf4/ocs-rhel9-operator:1786705802
  • odf4/odf-cli-rhel9:1786705938
  • odf4/odf-console-rhel9:1786706577
  • odf4/odf-cosi-sidecar-rhel9:1786706125
  • odf4/odf-csi-addons-rhel9-operator:1786706177
  • odf4/odf-csi-addons-sidecar-rhel9:1786706188
  • odf4/odf-multicluster-console-rhel9:1786706679
  • odf4/odf-multicluster-rhel9-operator:1786706357
  • odf4/odf-must-gather-rhel9:1786706612
  • odf4/odf-rhel9-operator:1786706644
  • odf4/odr-rhel9-operator:1786706659
  • odf4/rook-ceph-rhel9-operator:1786706880
  • RHSA-2026:57590
  • RHSA-2026:50850
  • RHSA-2026:42815
  • RHSA-2026:51162
  • RHSA-2026:48126
  • RHSA-2026:49642
  • RHSA-2026:38187
  • RHSA-2026:60520
  • RHSA-2026:60446
  • RHSA-2026:60477
  • RHSA-2026:51038
  • RHSA-2026:60441
  • RHSA-2026:56431

Official advisory · high-confidence parse· fetched 3 days ago·verify at source

Mitigation

Upgrade to a fixed release: 5.0.1, rh-podman-desktop-0:1.1.2-1.el10_2, ansible-automation-platform/automation-portal:1785854226, ansible-automation-platform/automation-portal:1784622951, ansible-automation-platform/bootc-automation-portal-rhel9:1786006573, rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1785332825. That is the remediation for this advisory.

The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.

Official advisory · high-confidence parse· fetched 3 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.