MEDIUM
GHSA-jxhh-4648-vpp3
FPDI allows Memory Exhaustion (OOM) in PDF Parser which leads to Denial of Service
Quick fix
GHSA-jxhh-4648-vpp3 — setasign/fpdi: upgrade to the fixed version with the command below.
composer require setasign/fpdi:^2.6.4Details
### Impact This is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion. Repeated attacks can lead to sustained service unavailability.
### Patches Fixed as of version 2.6.4
### Workarounds No.
Are you affected?
Enter the version of the package you're using.