CVE-2026-71439CWE-1322CWE-606

CVE-2026-71439

published August 7, 2026

CVSS
5.3
EPSS
0%
Percentile
36.0
In the wild
Unconfirmed
What it is

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage or JavaScript process for long periods of time, potentially until the process is killed from memory exhaustion. This issue is fixed in version 11.16.1.

The record
Technical detail
CVSS
5.3 · NONE
CVSS v4.0
Not supplied
EPSS
0.00430 · 36.0th percentile
Weaknesses
CWE-1322 · Use of Blocking Code in Single-threaded, Non-blocking Context; CWE-606 · Unchecked Input for Loop Condition
Published
2026-08-07T02:18Z
References (4)
EPSS history
Timeline
  • 06 AUG 20:01Z
    Mermaid radar diagrams are vulnerable to DoS
    cvelistv5