CVE-2026-44897: Inline Delimiter Regex Missing Escape Handlingcve-2026-44897-inline-delimiter-regex-missing-escape-handling
This regex pattern for an inline delimited span uses `.+?` which does not atomically consume backslash-escape sequences. An attacker can craft input like `$\$<payload>` to split the escape sequence `\$` across the match boundary: the `\` is absorbed as math content while the `$` closes the span prematurely. Content that should be inside the sanitized span is