MEDIUM
GHSA-2mgw-7q6p-8grg
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
Quick fix
GHSA-2mgw-7q6p-8grg — setasign/fpdi: upgrade to the fixed version with the command below.
composer require setasign/fpdi:^2.6.7Details
### Impact This is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion or a script time-out. Repeated attacks can lead to sustained service unavailability.
### Patches Fixed as of version 2.6.7
### Workarounds No.
### References No.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/Setasign/FPDI/security/advisories/GHSA-2mgw-7q6p-8grg[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-45802[ADVISORY]
- https://github.com/Setasign/FPDI/commit/1695cfcc7e01fe844a7296b3de90855a3fa65be6[WEB]
- https://github.com/Setasign/FPDI[PACKAGE]
- https://github.com/Setasign/FPDI/releases/tag/v2.6.7[WEB]