---
id: CVE-2026-105219
title: >-
  Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service
  vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due
  to overlapping regex alternatives
summary: >-
  Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service
  vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due
  to overlapping regex alternatives. Attackers can supply a crafted .docx with
  an…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-1333
vendor: mwilliamson
product: mammoth.js
affected:
  - mammoth.js >= 1.3.0 < 1.12.3
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T18:16:34.777'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105219'
references:
  - url: 'https://github.com/mwilliamson/mammoth.js'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/mwilliamson/mammoth.js/blob/1.12.2/lib/styles/parser/tokeniser.js#L6-L30
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/mwilliamson/mammoth.js/commit/dc49225425c2c07de0a6dc3529f2386c82a032b4
    label: disclosure@vulncheck.com
  - url: 'https://github.com/mwilliamson/mammoth.js/issues/487'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mammoth-js-1.3.0-before-1.12.3-redos-via-style-map-tokeniser
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T18:02:47.900Z'
---

## Overview

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
