Sceawere
Vulnerability Detail
CVE-2026-105219UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Mammoth.js Regex Denial of Service
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- mwilliamson
- Product
- mammoth.js
- Attack Type
- Inefficient Regular Expression Complexity
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-04T18:16:34.777Z",
"pubdate": "2026-10-04T18:16:34.777Z",
"executiveSummary": "Mammoth.js versions 1.3.0 through 1.12.2 contain a Regular Expression Denial of Service (ReDoS) vulnerability located within the style map tokeniser.\nThe vulnerability stems from the use of overlapping regular expression alternatives that trigger catastrophic backtracking when processing maliciously crafted input.\nAn attacker can exploit this by supplying a specially crafted .docx file containing an unterminated quoted string comprised of repeated backslash escape sequences.\nSuccessful exploitation results in the exhaustion of CPU resources, effectively blocking the Node.js event loop and causing a denial of service condition.\nThe impact is significant, as the single-threaded nature of the Node.js runtime makes the application unresponsive to all incoming requests during the execution of the inefficient regex match.\nThis vulnerability does not require authentication or elevated privileges, as the attack vector is embedded within the document parsing process itself, making it accessible to any user capable of submitting a .docx file for processing.",
"technicalDetails": "The vulnerability resides in lib/styles/parser/tokeniser.js within the Mammoth.js library. The core issue is an inefficient regular expression used to parse tokens in the style map definition.\nThe regex engine encounters overlapping alternatives when processing a string that features unterminated quotes and nested or repeated backslash sequences. This configuration forces the engine into a state of catastrophic backtracking.\nIn catastrophic backtracking, the regex engine attempts to explore an exponential number of paths to find a match, which is impossible given the malformed input. Because this execution occurs synchronously within the Node.js event loop, the process becomes entirely consumed by the regex evaluation, leading to a complete freeze of the application's responsiveness.\nThe attack flow begins when an attacker uploads or submits a malicious .docx document that includes a style map containing an unterminated quoted string. This string is structured with specific, repeated backslash escape characters designed to trigger the ambiguity in the vulnerable regex pattern.\nWhen Mammoth.js attempts to parse this document, the tokeniser processes the style map string. Upon encountering the crafted sequence, the regex engine's performance degrades from linear time complexity to exponential time complexity.\nBecause Node.js is single-threaded, the blocked event loop prevents the application from handling any other asynchronous operations, such as network I/O, database queries, or incoming requests. This state persists until the regex match either completes or the process is forcibly terminated by a supervisor or watchdog mechanism.\nThe vulnerability affects all versions of Mammoth.js starting from 1.3.0 up to, but not including, 1.12.3. No specific privilege levels or authentication mechanisms are required to trigger this vulnerability, as it is inherent to the library's document parsing logic. The exposure is limited to environments where the library is used to parse user-supplied .docx documents."
}