HIGH
mwilliamson
CVE published 2026-10-04
CVE-2026-105219
CVE-2026-105219 is a high-severity vulnerability in Mammoth.js, a JavaScript library for converting .docx files to HTML. The vulnerability is caused by a regular expression denial of service (ReDoS) in the style map tokeniser. An attacker can supply a crafted .docx file with an unterminated quoted string of repeated backslash escapes to block the Node.js event loop.