Bug 2512242 (CVE-2026-71436) - CVE-2026-71436 mermaid: Mermaid XY Charts: Denial of Service via invalid X-Axis parameters
Summary: CVE-2026-71436 mermaid: Mermaid XY Charts: Denial of Service via invalid X-Ax...
Keywords:
Status: NEW
Alias: CVE-2026-71436
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-06 22:24 UTC by OSIDB Bzimport
Modified: 2026-08-10 09:59 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-06 22:24:23 UTC
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because each loop iteration appends an element to an array, this generally causes a RangeError to appear after a few seconds, but it may instead cause the page or JavaScript process to crash from memory exhaustion, depending on the environment. This issue is fixed in versions 10.9.8 and 11.16.1.


Note You need to log in before you can comment on or make changes to this bug.