CVE-2026-105219
Received Received - Intake

Regular Expression Denial of Service in Mammoth.js

Vulnerability report for CVE-2026-105219, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mammoth.js mammoth.js to 1.12.3 (exc)
mammoth.js mammoth.js to 1.12.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Regular Expression Denial of Service (ReDoS) vulnerability in Mammoth.js versions 1.3.0 through 1.12.2. It occurs in the style map tokeniser (lib/styles/parser/tokeniser.js) where overlapping regex alternatives allow exponential backtracking when parsing maliciously crafted .docx files with unterminated quoted strings containing repeated backslash escapes. This can block the Node.js event loop for extended periods.

Detection Guidance

To detect this vulnerability, monitor for high CPU usage or frozen Node.js processes when processing .docx files with mammoth.js. Check logs for mammoth.convertToHtml() operations on untrusted documents. Use the fixed version 1.12.3 or later and verify the regex in lib/styles/parser/tokeniser.js has been updated.

Impact Analysis

If you process untrusted .docx files using affected Mammoth.js versions, an attacker could supply a specially crafted file to freeze your application for minutes to hours. This disrupts service availability and may crash the Node.js process. Applications handling email attachments or user uploads are particularly at risk.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR and HIPAA by enabling denial of service attacks. GDPR requires systems to ensure availability of services, while HIPAA mandates safeguards against disruptions. A ReDoS attack could violate these requirements by degrading or blocking service availability.

Mitigation Strategies
  • Upgrade mammoth.js to version 1.12.3 or later to apply the regex fix.
  • Disable embedded style map parsing by setting includeEmbeddedStyleMap: false in the library configuration.
  • Process untrusted .docx files in a separate thread or worker with a timeout to limit event loop blocking.
  • Avoid using mammoth.js with untrusted documents until patched or mitigated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105219. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart