PatchSiren cyber security CVE debrief
CVE-2026-105219 mwilliamson CVE debrief
CVE-2026-105219 is a high-severity vulnerability in Mammoth.js, a JavaScript library for converting .docx files to HTML. The vulnerability is caused by a regular expression denial of service (ReDoS) in the style map tokeniser. An attacker can supply a crafted .docx file with an unterminated quoted string of repeated backslash escapes to block the Node.js event loop.
- Vendor
- mwilliamson
- Product
- mammoth.js
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders responsible for Node.js applications that use Mammoth.js, particularly those that process .docx files, should assess exposure to this vulnerability and prioritize verification and potential updates.
Why it matters
CVE-2026-105219 is a high-severity vulnerability in Mammoth.js that could allow denial of service attacks. Defenders should verify the version in use, assess exposure, and prioritize updates to prevent potential event loop blocking.
- Denial of service attacks may be possible by supplying crafted .docx files
- Verification of Mammoth.js version and exposure is necessary
- Potential for event loop blocking requires attention from Node.js application defenders
Technical summary
The vulnerability is caused by a regular expression denial of service (ReDoS) in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. An attacker can supply a crafted .docx file with an unterminated quoted string of repeated backslash escapes to block the Node.js event loop. Defenders should prioritize verifying the version of Mammoth.js in use and assessing exposure to this vulnerability, particularly in systems that process .docx files. The issue was fixed in version 1.12.3.
Defensive priority
Defenders should prioritize verifying the version of Mammoth.js in use and assessing exposure to this vulnerability, particularly in systems that process .docx files.
Recommended defensive actions
- Verify the version of Mammoth.js in use and assess exposure to this vulnerability
- Update to version 1.12.3 or later if possible
- Monitor for potential denial of service attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is caused by overlapping regex alternatives in the style map tokeniser in lib/styles/parser/tokeniser.js. The issue was fixed in version 1.12.3. Defenders should verify the version in use and assess exposure to this vulnerability, particularly in systems that process .docx files. The vulnerability allows for denial of service attacks by supplying crafted .docx files with unterminated quoted strings of repeated backslash escapes.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105219 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105219
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105219 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105219
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/mwilliamson/mammoth.js
-
Source reference
Unverified legacy reference
URL: https://github.com/mwilliamson/mammoth.js/blob/1.12.2/lib/styles/parser/tokeniser.js
-
Source reference
Unverified legacy reference
URL: https://github.com/mwilliamson/mammoth.js/commit/dc49225425c2c07de0a6dc3529f2386c82a032b4
-
Source reference
Unverified legacy reference
URL: https://github.com/mwilliamson/mammoth.js/issues/487
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/mammoth-js-1.3.0-before-1.12.3-redos-via-style-map-tokeniser
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.