OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-105219

HIGH · CVSS 7.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-04 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Mammoth.js versions prior to 1.12.3 are vulnerable to a regular expression denial of service (ReDoS) attack, which can be triggered by supplying a specially crafted .docx file containing an unterminated quoted string with repeated backslash escapes. This vulnerability can lead to a blockage of the Node.js event loop, potentially disrupting service availability. Organizations using affected versions of Mammoth.js should prioritize patching to mitigate the risk of service interruption.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105219
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.