Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6m6c-36f7-fhxh | Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS |
Tue, 09 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 01 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mermaid_project:mermaid:*:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
Sat, 30 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mermaid Project
Mermaid Project mermaid |
|
| Vendors & Products |
Mermaid Project
Mermaid Project mermaid |
Fri, 29 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0. | |
| Title | Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS | |
| Weaknesses | CWE-835 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T16:17:31.324Z
Reserved: 2026-04-17T12:59:15.740Z
Link: CVE-2026-41150
Updated: 2026-05-29T16:13:40.925Z
Status : Analyzed
Published: 2026-05-29T15:16:22.673
Modified: 2026-06-01T18:37:37.857
Link: CVE-2026-41150
OpenCVE Enrichment
Updated: 2026-05-30T20:45:05Z
Github GHSA