mammoth is vulnerable to Denial of Service (DoS)
65
Medium Risk
When resolving list numbering, the parser follows numStyleLink references between numbering definitions to locate a level. A numbering definition that links to itself, directly or through a cycle, causes the lookup to recurse without termination. Converting a crafted document exhausts the call stack and consumes excessive CPU and memory, crashing or hanging the conversion. The fix tracks already-visited numbering identifiers and stops when a cycle is detected.
You are affected if you are using a version that falls within the vulnerable range and you convert untrusted or externally supplied documents.
mammoth is vulnerable to Denial of Service (DoS) in versions 1.4.8 - 1.12.0.
Upgrade the mammoth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant