PatchSiren

mwilliamson CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mwilliamson CVE published 2026-10-04

CVE-2026-105219

CVE-2026-105219 is a high-severity vulnerability in Mammoth.js, a JavaScript library for converting .docx files to HTML. The vulnerability is caused by a regular expression denial of service (ReDoS) in the style map tokeniser. An attacker can supply a crafted .docx file with an unterminated quoted string of repeated backslash escapes to block the Node.js event loop.