GHSA-rhh3-jpg6-66xh

Suggest an improvement
Source
https://github.com/advisories/GHSA-rhh3-jpg6-66xh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-rhh3-jpg6-66xh/GHSA-rhh3-jpg6-66xh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rhh3-jpg6-66xh
Aliases
Downstream
CGA (40)
MINI (2)
Published
2026-08-06T20:01:07Z
Modified
2026-09-10T03:51:14Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L CVSS Calculator
Summary
Mermaid radar diagrams are vulnerable to DoS
Details

Impact

Mermaid radar diagrams allow arbitrary large values for ticks, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory.

Proof-of-concept

radar-beta
  axis a, b
  curve c {1, 1}
  ticks 1000000000

Patches

Has the problem been patched? What versions should users upgrade to?

This problem has been patched by https://github.com/mermaid-js/mermaid/commit/59b22fad2b3bb04f87a476c84a8a2b24679e607e, which was released in Mermaid v11.16.1

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

There are no known workarounds without updating to a patched version of mermaid.

References

Are there any links users can visit to find out more?

Database specific
{
    "cwe_ids":  [
        "CWE-1322",
        "CWE-606"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-06T20:01:07Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / mermaid

Package

Affected ranges

Type
SEMVER
Events
Introduced
11.6.0
Fixed
11.16.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-rhh3-jpg6-66xh/GHSA-rhh3-jpg6-66xh.json"