Description
Mermaid radar diagrams allow arbitrary large values for ticks, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory.
Recommendation
Update the mermaid package to the latest compatible version. Followings are version details:
- Affected version(s): >= 11.6.0, < 11.16.1
- Patched version(s): 11.16.1
References
Related Issues
- Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS - CVE-2026-41150
- Mermaid Architecture diagrams are vulnerable to prototype pollution - CVE-2026-71437
- Mermaid XY Charts are vulnerable to an infinite loop DoS - CVE-2026-71436
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
You might also like:
- Tags:
- npm
- mermaid
Anything's wrong? Let us know Last updated on August 06, 2026


