PT-2026-68804 · Mermaid · Mermaid
CVE-2026-71436
·
Published
2026-08-06
·
Updated
2026-08-07
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L |
Name of the Vulnerable Software and Affected Versions
Mermaid versions 10.6.0 through 10.9.7
Mermaid versions 11.0.0 through 11.16.0
Description
Mermaid XY Charts are subject to a denial of service via an infinite loop in the
setXAxisRangeData() function when an X-Axis is configured with invalid parameters. During the loop, elements are continuously appended to an array, which typically results in a RangeError after several seconds or may cause the JavaScript process or page to crash due to memory exhaustion, depending on the environment.Recommendations
Update Mermaid versions 10.6.0 through 10.9.7 to version 10.9.8.
Update Mermaid versions 11.0.0 through 11.16.0 to version 11.16.1.
Exploit
Fix
DoS
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mermaid