High severityNVD Advisory· Published Oct 7, 2025· Updated Oct 9, 2025
CVE-2025-11362
CVE-2025-11362
Description
Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pdfmakenpm | >= 0.3.0-beta.1, < 0.3.0-beta.17 | 0.3.0-beta.17 |
Affected products
19- osv-coords18 versionspkg:apk/chainguard/kibana-7pkg:apk/chainguard/kibana-7-bitnamipkg:apk/chainguard/kibana-8.17pkg:apk/chainguard/kibana-8.17-bitnamipkg:apk/chainguard/kibana-8.17-iamguardedpkg:apk/chainguard/kibana-8.18pkg:apk/chainguard/kibana-8.18-bitnamipkg:apk/chainguard/kibana-8.18-iamguardedpkg:apk/chainguard/kibana-8.19pkg:apk/chainguard/kibana-8.19-bitnamipkg:apk/chainguard/kibana-8.19-iamguardedpkg:apk/chainguard/kibana-9.0pkg:apk/chainguard/kibana-9.0-bitnamipkg:apk/chainguard/kibana-9.0-iamguardedpkg:apk/chainguard/kibana-9.1pkg:apk/chainguard/kibana-9.1-bitnamipkg:apk/chainguard/kibana-9.1-iamguardedpkg:npm/pdfmake
< 7.17.29-r4+ 17 more
- (no CPE)range: < 7.17.29-r4
- (no CPE)range: < 7.17.29-r4
- (no CPE)range: < 8.17.10-r1
- (no CPE)range: < 8.17.10-r1
- (no CPE)range: < 8.17.10-r1
- (no CPE)range: < 8.18.8-r0
- (no CPE)range: < 8.18.8-r0
- (no CPE)range: < 8.18.8-r0
- (no CPE)range: < 8.19.5-r0
- (no CPE)range: < 8.19.5-r0
- (no CPE)range: < 8.19.5-r0
- (no CPE)range: < 9.0.8-r0
- (no CPE)range: < 9.0.8-r0
- (no CPE)range: < 9.0.8-r0
- (no CPE)range: < 9.1.5-r0
- (no CPE)range: < 9.1.5-r0
- (no CPE)range: < 9.1.5-r0
- (no CPE)range: >= 0.3.0-beta.1, < 0.3.0-beta.17
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.