CVE-2026-71436

MEDIUM

Mermaid XY Charts - Denial of Service via Invalid X-Axis Parameters

Title source: manual
STIX 2.1

Description

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because each loop iteration appends an element to an array, this generally causes a RangeError to appear after a few seconds, but it may instead cause the page or JavaScript process to crash from memory exhaustion, depending on the environment. This issue is fixed in versions 10.9.8 and 11.16.1.

Scores

CVSS v4 5.3
EPSS 0.0033
EPSS Percentile 25.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1325 CWE-835
Status published
Products (4)
mermaid-js/mermaid >= 10.6.0, < 10.9.8
mermaid-js/mermaid >= 11.0.0-alpha.1, < 11.16.1
npm/mermaid 10.6.0 - 10.9.8npm
npm/mermaid 11.0.0-alpha.1 - 11.16.1npm
Published Aug 06, 2026
Tracked Since Aug 07, 2026