Regular Expression Denial of Service in Mammoth.js by Mwilliamson
CVE-2026-105219
8.7HIGH
What is CVE-2026-105219?
Mammoth.js versions before 1.12.3 are susceptible to a regular expression denial of service vulnerability within the style map tokeniser. This issue arises from overlapping regex alternatives that can be exploited by attackers. By crafting a specific .docx file containing an unterminated quoted string with multiple backslash escapes in the mammoth/style-map, an attacker could effectively block the Node.js event loop. This vulnerability poses a significant risk to applications using affected versions, highlighting the need for timely updates and patches.
Affected Version(s)
mammoth.js 1.3.0 < 1.12.3
