Description
Mermaid v11.14.0 and earlier are vulnerable to a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
Affected version(s): **<= 10.9.5 >= 11.0.0-alpha.1, <= 11.14.0** Patched version(s): **10.9.6 11.15.0**
References
Could your website be exposed too?
SmartScanner can check your website for Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Mermaid XY Charts are vulnerable to an infinite loop DoS - CVE-2026-71436
- Mermaid radar diagrams are vulnerable to DoS - CVE-2026-71439
- jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs - CVE-2026-4598
- Mermaid Architecture diagrams are vulnerable to prototype pollution - CVE-2026-71437
You might also like:
See something that needs correcting? Let us knowUpdated June 09, 2026


