Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71436

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because each loop iteration appends an element to an array, this generally causes a RangeError to appear after a few seconds, but it may instead cause the page or JavaScript process to crash from memory exhaustion, depending on the environment. This issue is fixed in versions 10.9.8 and 11.16.1.

A flaw was found in Mermaid XY Charts. A remote attacker could exploit this by providing invalid parameters when configuring an X-Axis. This could lead to an infinite loop, causing a denial of service (DoS) due to memory exhaustion and potentially crashing the page or JavaScript process.

Отчет

Red Hat ships Mermaid (a JavaScript diagramming library) embedded in code-server based developer workbench images: OpenShift AI's odh-workbench-codeserver-datascience-cpu-py312 workbench image and OpenShift Dev Spaces' code-rhel9 image. The bundled version falls within the vulnerable range (>=10.6.0,<10.9.8 or below 11.16.1), exposing users who build interactive XY chart diagrams in the editor to a client-side denial of service (infinite loop / memory exhaustion) triggered by invalid X-Axis parameters. Resolution is delegated to the workbench/Dev Spaces image maintainers to bump the pinned mermaid dependency.

Меры по смягчению последствий

Avoid rendering or previewing untrusted Mermaid diagram content containing XY chart definitions with attacker-controlled X-Axis parameters in the affected workbench images until the pinned mermaid dependency is upgraded to 10.9.8+/11.16.1+.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktoprh-podman-desktop.gitNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9Not affected
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2512242mermaid: Mermaid XY Charts: Denial of Service via invalid X-Axis parameters

EPSS

Процентиль: 34%
0.00408
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
25 дней назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because each loop iteration appends an element to an array, this generally causes a RangeError to appear after a few seconds, but it may instead cause the page or JavaScript process to crash from memory exhaustion, depending on the environment. This issue is fixed in versions 10.9.8 and 11.16.1.

nvd
25 дней назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because each loop iteration appends an element to an array, this generally causes a RangeError to appear after a few seconds, but it may instead cause the page or JavaScript process to crash from memory exhaustion, depending on the environment. This issue is fixed in versions 10.9.8 and 11.16.1.

debian
25 дней назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...

github
25 дней назад

Mermaid XY Charts are vulnerable to an infinite loop DoS

EPSS

Процентиль: 34%
0.00408
Низкий

7.5 High

CVSS3