HIGH7.5
GHSA-rj3r-r7hh-jxfq
pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding
Quick fix
GHSA-rj3r-r7hh-jxfq — pdfmake: upgrade to the fixed version with the command below.
npm install pdfmake@0.3.0-beta.17Details
Versions of the package pdfmake from 0.3.0-beta.1 to before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-11362[ADVISORY]
- https://github.com/bpampuch/pdfmake/issues/2886[WEB]
- https://github.com/bpampuch/pdfmake/commit/741169634bf07730e010cd77477b6cc038e846ed[WEB]
- https://github.com/bpampuch/pdfmake[PACKAGE]
- https://security.snyk.io/vuln/SNYK-JS-PDFMAKE-10223297[WEB]