PT-2026-68807 · Mermaid · Mermaid
CVE-2026-71439
·
Published
2026-08-06
·
Updated
2026-08-07
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L |
Name of the Vulnerable Software and Affected Versions
Mermaid versions 11.6.0 through 11.16.0
Description
Radar Diagrams allow arbitrary large values for the
ticks parameter. This can lead to high CPU usage and freeze the rendering webpage or JavaScript process for extended periods, potentially resulting in the process being terminated due to memory exhaustion (OOM).Recommendations
Update to version 11.16.1.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mermaid