CVE-2026-71439: Mermaid radar diagrams are vulnerable to DoS
Mermaid radar diagrams allow arbitrary large values for ticks, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory.
References
- github.com/advisories/GHSA-rhh3-jpg6-66xh
- github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e
- github.com/mermaid-js/mermaid/pull/8022
- github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.16.1
- github.com/mermaid-js/mermaid/security/advisories/GHSA-rhh3-jpg6-66xh
- nvd.nist.gov/vuln/detail/CVE-2026-71439
Code Behaviors & Features
Detect and mitigate CVE-2026-71439 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →