PT-2026-68807 · Mermaid · Mermaid

CVE-2026-71439

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Name of the Vulnerable Software and Affected Versions Mermaid versions 11.6.0 through 11.16.0
Description Radar Diagrams allow arbitrary large values for the ticks parameter. This can lead to high CPU usage and freeze the rendering webpage or JavaScript process for extended periods, potentially resulting in the process being terminated due to memory exhaustion (OOM).
Recommendations Update to version 11.16.1.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71439
GHSA-RHH3-JPG6-66XH

Affected Products

Mermaid