← Back to CVE List
CVE-2026-105219NVD
Vulnerability Summary
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.
CVSS v4.0 Base Metrics — Score 8.7 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- mwilliamson mammoth.js >= 1.3.0 and < 1.12.3
- mwilliamson mammoth.js 1.12.3
External References
- https://github.com/mwilliamson/mammoth.js/issues/487
- https://github.com/mwilliamson/mammoth.js/commit/dc49225425c2c07de0a6dc3529f2386c82a032b4
- https://github.com/mwilliamson/mammoth.js/blob/1.12.2/lib/styles/parser/tokeniser.js#L6-L30
- https://github.com/mwilliamson/mammoth.js
- https://www.vulncheck.com/advisories/mammoth-js-1.3.0-before-1.12.3-redos-via-style-map-tokeniser