Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-105219

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Oct 04, 2026
Vendor unknown

Description

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.

References