VDB
Sign up
MEDIUM

GHSA-mx3p-fhpw-x6rv

TCPDF vulnerable to Regular Expression Denial of Service

Quick fix

GHSA-mx3p-fhpw-x6rv — tecnickcom/tcpdf: upgrade to the fixed version with the command below.

composer require tecnickcom/tcpdf:^6.7.5

Details

TCPDF version <= 6.7.4 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tecnickcom/tcpdf
Introduced in: 0Fixed in: 6.7.5
Fixcomposer require tecnickcom/tcpdf:^6.7.5

References