Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71439

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage or JavaScript process for long periods of time, potentially until the process is killed from memory exhaustion. This issue is fixed in version 11.16.1.

A flaw was found in Mermaid. Mermaid Radar Diagrams are susceptible to a denial of service vulnerability. A remote attacker could exploit this by providing excessively large values for the 'ticks' parameter. This can lead to high CPU usage, causing the rendering webpage or JavaScript process to freeze and potentially terminate due to memory exhaustion.

Отчет

Red Hat ships Mermaid embedded in the same code-server based developer workbench images: OpenShift AI's odh-workbench-codeserver-datascience-cpu-py312 workbench image and OpenShift Dev Spaces' code-rhel9 image. The bundled version (>=11.6.0,<11.16.1) exposes users who render Mermaid Radar diagrams with excessively large 'ticks' values to a client-side denial of service through high CPU usage and potential process termination.

Меры по смягчению последствий

Avoid rendering untrusted Mermaid diagram content containing Radar diagrams with attacker-controlled 'ticks' parameters in the affected workbench images until the pinned mermaid dependency is upgraded to 11.16.1 or later.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktoprh-podman-desktop.gitNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9Fix deferred
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1050
https://bugzilla.redhat.com/show_bug.cgi?id=2512273mermaid: Mermaid: Denial of Service via Radar Diagrams 'ticks' parameter

EPSS

Процентиль: 32%
0.00391
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
25 дней назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage or JavaScript process for long periods of time, potentially until the process is killed from memory exhaustion. This issue is fixed in version 11.16.1.

nvd
25 дней назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage or JavaScript process for long periods of time, potentially until the process is killed from memory exhaustion. This issue is fixed in version 11.16.1.

debian
25 дней назад

Mermaid is a JavaScript tool that uses Markdown-inspired text to creat ...

github
25 дней назад

Mermaid radar diagrams are vulnerable to DoS

EPSS

Процентиль: 32%
0.00391
Низкий

6.5 Medium

CVSS3