PT-2026-68804 · Mermaid · Mermaid

CVE-2026-71436

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Name of the Vulnerable Software and Affected Versions Mermaid versions 10.6.0 through 10.9.7 Mermaid versions 11.0.0 through 11.16.0
Description Mermaid XY Charts are subject to a denial of service via an infinite loop in the setXAxisRangeData() function when an X-Axis is configured with invalid parameters. During the loop, elements are continuously appended to an array, which typically results in a RangeError after several seconds or may cause the JavaScript process or page to crash due to memory exhaustion, depending on the environment.
Recommendations Update Mermaid versions 10.6.0 through 10.9.7 to version 10.9.8. Update Mermaid versions 11.0.0 through 11.16.0 to version 11.16.1.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71436
GHSA-2V8P-3F2J-5MP7

Affected Products

Mermaid