Mermaid · Mermaid · CVE-2026-41150
**Name of the Vulnerable Software and Affected Versions**
Mermaid versions 11.14.0 and earlier
Mermaid versions prior to 10.9.6
**Description**
A denial-of-service issue occurs when rendering gantt charts if the `excludes` attribute is used to exclude all dates. While `mermaid.parse` is not affected, the issue is triggered when calling the `ganttDb.getTasks()` function during diagram rendering.
**Recommendations**
Update to version 11.15.0.
Update to version 10.9.6.