VYPR
High severity7.5NVD Advisory· Published Mar 10, 2026· Updated May 7, 2026

CVE-2026-26801

CVE-2026-26801

Description

Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method allowing server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pdfmakenpm
>= 0.3.0-beta.2, < 0.3.60.3.6

Affected products

21
  • Pdfmake/Pdfmake20 versions
    cpe:2.3:a:pdfmake:pdfmake:*:*:*:*:*:*:*:*+ 19 more
    • cpe:2.3:a:pdfmake:pdfmake:*:*:*:*:*:*:*:*range: >=0.3.1,<=0.3.5
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:-:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta10:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta11:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta12:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta13:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta14:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta15:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta16:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta17:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta18:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta19:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta4:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta5:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta6:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta7:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta8:*:*:*:*:*:*
    • cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta9:*:*:*:*:*:*
  • pdfmake/pdfmakedescription

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.