Summary
Mermaid XY Charts are vulnerable to an infinite loop DoS
Advisory details
Impact
Mermaid XY Charts are vulnerable to an infinite loop DoS attack in the setXAxisRangeData(), when configuring an X-Axis with invalid parameters.
As each loop appends an element to an array, this would generally only cause an RangeError: Invalid array length to appear after a few seconds, but may cause the page/JavaScript process to crash due to memory exhaustion, depending on the environment.
Proof-of-concept
xychart
x-axis 1 --> 1
line [1, 2]
Patches
This has been patched in https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289 and released in Mermaid v11.16.1.
A backport has been made for the v10 branch in ef60adc837d9d5107af21285f01e83dea309bd0a and was released in Mermaid v10.9.8
Workarounds
There are no known workarounds. Please update to the latest version or apply the patch.
References
References
- https://github.com/advisories/GHSA-2v8p-3f2j-5mp7
- https://github.com/mermaid-js/mermaid/security/advisories/GHSA-2v8p-3f2j-5mp7
- https://github.com/mermaid-js/mermaid/pull/8022
- https://github.com/mermaid-js/mermaid/commit/630aa7e5dd417e1f56bff2a1ce8df2c5ad08d289
- https://github.com/mermaid-js/mermaid/commit/ef60adc837d9d5107af21285f01e83dea309bd0a
- https://github.com/mermaid-js/mermaid/releases/tag/mermaid@11.16.1
- https://github.com/mermaid-js/mermaid/releases/tag/v10.9.8
Related vulnerabilities
All Supply chain →- HIGHCVE-2026-61556
LiquidJS has an infinite loop vulnerability in its `strip_html` filter
- MEDIUMCVE-2026-84309
pypdf: Possible infinite loop for TreeObject.insert_child
- HIGHCVE-2026-54623
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
- HIGHCVE-2026-63202
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
- HIGHCVE-2026-63124
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
- MEDIUMCVE-2026-68499
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)