CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105219

HIGHCVSS 7.5NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in ma

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105219 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105219

HIGHCVSS 7.5NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in ma

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]