CVE-2026-103043
Received Received - Intake

anchorme Regex DoS via IPv6 Host Extraction

Vulnerability report for CVE-2026-103043, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a regular expression denial of service (ReDoS) issue in the anchorme library version 3.0.8. It occurs due to catastrophic backtracking in the IPv6 host extraction regex. Attackers can exploit this by sending input strings with repeated patterns, causing the regex engine to perform excessive backtracking. This blocks the Node.js event loop, preventing the server from processing other requests and effectively denying service to legitimate users.

Detection Guidance

This vulnerability can be detected by monitoring for excessive CPU usage or event loop delays in Node.js applications using the anchorme library. Check for repeated patterns in input strings that may trigger catastrophic backtracking in the IPv6 host extraction regex.

Impact Analysis

If you are using the affected version of anchorme, this vulnerability can cause your application to become unresponsive or crash when processing malicious input. This leads to downtime, degraded performance, and potential loss of service for users. It may also expose your system to further attacks if the event loop remains blocked.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it is a technical denial-of-service issue in a software library. However, if exploited, it could lead to service unavailability, potentially violating availability requirements in GDPR Article 32 or HIPAA Security Rule Section 164.308(a)(7).

Mitigation Strategies

Immediately update the anchorme library to version 3.0.9 or later, which patches the regex vulnerability. If updating is not possible, consider disabling the IPv6 host extraction feature or implementing input validation to prevent malicious patterns from reaching the regex engine.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103043. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart