Regular Expression Denial of Service in Mammoth.js by Mwilliamson
CVE-2026-105219

8.7HIGH

Key Information:

Vendor
CVE Published:
4 October 2026

What is CVE-2026-105219?

Mammoth.js versions before 1.12.3 are susceptible to a regular expression denial of service vulnerability within the style map tokeniser. This issue arises from overlapping regex alternatives that can be exploited by attackers. By crafting a specific .docx file containing an unterminated quoted string with multiple backslash escapes in the mammoth/style-map, an attacker could effectively block the Node.js event loop. This vulnerability poses a significant risk to applications using affected versions, highlighting the need for timely updates and patches.

Affected Version(s)

mammoth.js 1.3.0 < 1.12.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siyang Wu
.