CVE-2026-71439: Mermaid-Js Mermaid
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage or JavaScript process for long periods of time, potentially until the process is killed from memory exhaustion. This issue is fixed in version 11.16.1.
Affected products
- Mermaid-Js Mermaid: from 11.6.0, before 11.16.1 (fixed in 11.16.1)
Published 2026-08-06. Last modified 2026-09-08.