High severity7.5NVD Advisory· Published Mar 10, 2026· Updated May 7, 2026
CVE-2026-26801
CVE-2026-26801
Description
Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method allowing server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pdfmakenpm | >= 0.3.0-beta.2, < 0.3.6 | 0.3.6 |
Affected products
21cpe:2.3:a:pdfmake:pdfmake:*:*:*:*:*:*:*:*+ 19 more
- cpe:2.3:a:pdfmake:pdfmake:*:*:*:*:*:*:*:*range: >=0.3.1,<=0.3.5
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:-:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta10:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta11:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta12:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta13:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta14:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta15:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta16:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta17:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta18:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta19:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta5:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta6:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta7:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta8:*:*:*:*:*:*
- cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta9:*:*:*:*:*:*
- pdfmake/pdfmakedescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/bpampuch/pdfmake/pull/2920nvdIssue TrackingPatchWEB
- mariopepe.github.io/cve-2026-26801-pdfmake-ssrfnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-wp52-r2fp-4vmrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-26801ghsaADVISORY
- github.com/bpampuch/pdfmake/blob/master/src/URLResolver.jsnvdProductWEB
- github.com/bpampuch/pdfmake/releases/tag/0.3.6nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.