HIGH7.5
GHSA-w95c-7994-ghpr
TCPDF has incorrect comparison
Quick fix
GHSA-w95c-7994-ghpr — tecnickcom/tcpdf: upgrade to the fixed version with the command below.
composer require tecnickcom/tcpdf:^6.8.0Details
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tecnickcom/tcpdf
Introduced in:
0Fixed in: 6.8.0Fix
composer require tecnickcom/tcpdf:^6.8.0References
- https://nvd.nist.gov/vuln/detail/CVE-2024-56522[ADVISORY]
- https://github.com/tecnickcom/TCPDF/commit/d54b97cec33f4f1a5ad81119a82085cad93cec89[WEB]
- https://github.com/tecnickcom/TCPDF[PACKAGE]
- https://github.com/tecnickcom/TCPDF/compare/6.7.8...6.8.0[WEB]
- https://lists.debian.org/debian-lts-announce/2025/06/msg00004.html[WEB]
- https://tcpdf.org[WEB]
- https://www.php.net/manual/en/types.comparisons.php[WEB]