OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103043

HIGH · CVSS 7.5 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects the anchorme library up to version 3.0.8, which is susceptible to a regular expression denial of service (ReDoS) attack through its IPv6 host extraction regex. By exploiting this flaw, attackers can craft specific input strings that trigger catastrophic backtracking, leading to significant delays in the Node.js event loop and potentially disrupting service for legitimate users. Organizations utilizing this library, particularly those relying on Node.js for web applications, should prioritize patching to mitigate the risk of service disruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103043
Severity
HIGH
CVSS
7.5
EPSS
0.45%

Original NVD Description

anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.