MEDIUM
GHSA-mx3p-fhpw-x6rv
TCPDF vulnerable to Regular Expression Denial of Service
Quick fix
GHSA-mx3p-fhpw-x6rv — tecnickcom/tcpdf: upgrade to the fixed version with the command below.
composer require tecnickcom/tcpdf:^6.7.5Details
TCPDF version <= 6.7.4 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tecnickcom/tcpdf
Introduced in:
0Fixed in: 6.7.5Fix
composer require tecnickcom/tcpdf:^6.7.5References
- https://nvd.nist.gov/vuln/detail/CVE-2024-22640[ADVISORY]
- https://github.com/tecnickcom/TCPDF/commit/05f3a28f4a7905019469e040cf77e53d6aa7f679[WEB]
- https://github.com/tecnickcom/TCPDF[PACKAGE]
- https://github.com/zunak/CVE-2024-22640[WEB]
- https://lists.debian.org/debian-lts-announce/2025/06/msg00004.html[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LIB3R2WB7XPW2I4PGVMZ3VLFLRHOK4RB[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LIB3R2WB7XPW2I4PGVMZ3VLFLRHOK4RB[WEB]