A Word document can block a Node.js event loop when Mammoth.js parses its embedded style map. CVE-2026-105219 covers this denial-of-service flaw in the npm package mammoth, affecting versions from 1.3.0 up to, but excluding, 1.12.3. The October 4, 2026 CVE record lists September 1 as the date the issue became public. The identifier is new; the disclosure predates it. CVE record
For a team that accepts resumes, contracts, or customer documents, start with where conversion runs. If it shares the application's main event loop, a stalled conversion can delay other work on that process. If it runs in an isolated worker, investigate the impact on that worker and its queue. Node's execution model makes that distinction matter. Node.js guidance
Start by checking the deployed dependency version and the code that processes uploads. Then establish whether your conversion deadline actually stops the work.
The document can supply the style map
Mammoth converts DOCX documents into HTML. Style maps tell it how document styles should become HTML elements, such as turning a heading into an h1. Applications can supply those mappings themselves, and documents can contain embedded mappings. Mammoth documentation
In version 1.12.2, includeEmbeddedStyleMap defaults to true. The options reader combines an embedded map with the application's custom mappings before conversion. An application does not need a separate form that lets users edit style maps to accept this input. The uploaded document can carry it. Versioned options reader
The conversion code reads the embedded map, then calls parseStyleMap while preparing the HTML converter. That places document-controlled formatting instructions on a parsing path inside the application. Versioned conversion code
The tokenizer spends too long deciding how a string ends
The vulnerable code lives in lib/styles/parser/tokeniser.js. Its string-matching expression permits overlapping interpretations of escape characters. When a quoted value does not terminate, the regular-expression engine can revisit those interpretations repeatedly while trying to match it. That excessive backtracking consumes execution time before the parser can return an ordinary invalid-input result. Vulnerable tokenizer
The fix changes the string expression so the ordinary-character branch excludes backslashes, separating it from escape handling. It also adds regression coverage for unterminated strings and escape sequences. The release notes identify 1.12.3 as the release containing the correction. Maintainer patch
The reported impact is availability. The CVE record does not describe code execution or data theft. Whether someone can reach the vulnerable conversion through your application depends on its upload permissions and processing path. CVE record
A request timeout can leave the conversion running
Node executes JavaScript callbacks on an event loop. A synchronous regular expression can occupy that loop until it finishes. That means a timer scheduled on the same loop cannot interrupt the expression. Returning a promise from the conversion API does not move the parsing into a separate thread. A proxy can return a timeout to the client while the application keeps parsing. These are consequences of the execution model, not additional exploit conditions in the advisory. Node.js guidance
The maintainer recommends processing untrusted documents in a separate thread with a timeout even after this fix. Apply that recommendation as an enforceable deadline: the supervising code needs to be able to terminate the conversion worker. Verify that behavior in staging. Maintainer patch and release notes
Check the deployed conversion path before closing the ticket
For an application using an affected version:
- Find every deployed copy of
mammoth. Include document workers and indirect dependencies. Use the resolved dependency tree or deployment artifact to establish the version actually running. - Update affected installations to 1.12.3 or a later compatible release. Rebuild and redeploy each service that includes the library. Confirm the resulting artifact contains the corrected version. The fix is documented in the maintainer patch.
- Review embedded style-map handling. If the feature is unnecessary, consider
includeEmbeddedStyleMap: false. From the options-reader code, this prevents the embedded map from being added to the parsed mappings. Application-suppliedstyleMapvalues still remain, so this is a limited mitigation while patching. Options reader - Test isolation and recovery. In staging, verify that a conversion exceeding its deadline is terminated, unrelated requests remain responsive, and retries cannot repeatedly occupy all available conversion workers.
Keep the deployed version, release identifier, and recovery-test result with the remediation ticket. If you mark the finding as unreachable, record the actual call path and input restrictions that support that decision. Close the finding once the corrected version is deployed. Track any remaining worker-isolation work separately, with an owner and a test that proves a stuck conversion can be stopped.
