<Vulnerability name="CVE-2026-41150">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-05-29T13:54:52</PublicDate>
    <Bugzilla id="2483296" url="https://bugzilla.redhat.com/show_bug.cgi?id=2483296" xml:lang="en:us">
mermaid: Mermaid: Denial of Service via specially crafted gantt charts
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-835</CWE>
    <Details xml:lang="en:us" source="Mitre">
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the ganttDb.getTasks() (which is called when rendering a diagram). This vulnerability is fixed in 10.9.6 and 11.15.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Mermaid, a JavaScript tool used for creating diagrams and charts. This vulnerability allows a remote attacker to trigger a denial-of-service (DoS) condition. The attack occurs when a specially crafted gantt chart, which uses the `excludes` attribute to exclude all dates, is rendered. Successful exploitation can make the application unresponsive.
    </Details>
    <Statement xml:lang="en:us">
Moderate: This denial-of-service vulnerability in Mermaid affects applications that render untrusted gantt charts. Exploitation requires a user to process a specially crafted chart containing an `excludes` attribute that attempts to exclude all dates, leading to application unresponsiveness.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:podman_desktop:1">
        <ProductName>Red Hat Build of Podman Desktop</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rh-podman-desktop.git</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_ai">
        <ProductName>Red Hat OpenShift AI (RHOAI)</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_devspaces:3">
        <ProductName>Red Hat OpenShift Dev Spaces</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>devspaces/code-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-41150
https://nvd.nist.gov/vuln/detail/CVE-2026-41150
https://github.com/mermaid-js/mermaid/commit/a59ea56174712ee5430dfd5bc877cb5151f501a6
https://github.com/mermaid-js/mermaid/commit/faafb5d49106dd32c367f3882505f2dd625aa30e
https://github.com/mermaid-js/mermaid/releases/tag/mermaid%4011.15.0
https://github.com/mermaid-js/mermaid/releases/tag/v10.9.6
https://github.com/mermaid-js/mermaid/security/advisories/GHSA-6m6c-36f7-fhxh
    </References>
</Vulnerability>