Npm · Anchorme · CVE-2026-103043
**Name of the Vulnerable Software and Affected Versions**
anchorme versions prior to 3.0.9
**Description**
A regular expression denial of service occurs in the IPv6 host extraction regex due to catastrophic backtracking, which happens when a regex engine takes an exponential amount of time to process a string that nearly matches a pattern. Attackers can provide specially crafted input strings with repeated patterns to block the Node.js event loop, denying service to other requests.
**Recommendations**
Update anchorme to version 3.0.9 or later.