Description
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.
Published: 2026-10-04
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Mammoth.js versions 1.3.0 through 1.12.2 contain a regular expression denial‑of‑service vulnerability in the style map tokeniser. The overlapping regex alternatives cause catastrophic backtracking when parsing an unterminated quoted string of repeated backslashes, which blocks the Node.js event loop and makes the application unresponsive. This flaw is a classic RegEx ReDoS weakness, classified as CWE‑1333.

Affected Systems

The vulnerability affects the open‑source library mammoth.js distributed by David Williamson. Versions from 1.3.0 up to, but not including, 1.12.3 are impacted. Any project that imports or bundles these versions and processes .docx files supplied by external or untrusted sources is at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity and the lack of an EPSS score or KEV listing does not diminish the risk, especially for applications that parse Office files. Based on the description, the likely attack vector is by supplying a malicious .docx file, which can be performed remotely where the library is invoked, such as in web services or command‑line tools that accept user uploads. An attacker who can supply and trigger the regex backtracking consumes CPU time and halts the Node.js event loop, leading to denial of service across the application.

Generated by OpenCVE AI on October 4, 2026 at 18:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade mammoth.js to version 1.12.3 or later.
  • Restrict the source of .docx files to trusted origins; reject or quarantine untrusted documents.
  • Implement an application‑level timeout or rate limiting on the mammoth.js parsing routine to limit the impact of long‑running regex evaluations.

Generated by OpenCVE AI on October 4, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Mwilliamson
Mwilliamson mammoth.js
Vendors & Products Mwilliamson
Mwilliamson mammoth.js

Sun, 04 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.
Title Mammoth.js 1.3.0 before 1.12.3 ReDoS via Style Map Tokeniser
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mwilliamson Mammoth.js
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T17:09:54.186Z

Reserved: 2026-10-04T13:04:00.479Z

Link: CVE-2026-105219

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T18:16:34.777

Modified: 2026-10-04T18:16:34.777

Link: CVE-2026-105219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T19:00:14Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity