npm package
pdfmake
pkg:npm/pdfmake
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-26801 | Hig | 7.5 | >= 0.3.0-beta.2, < 0.3.6 | 0.3.6 | Mar 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method al | |
| CVE-2025-11362 | — | >= 0.3.0-beta.1, < 0.3.0-beta.17 | 0.3.0-beta.17 | Oct 7, 2025 | Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that trigger |
- affected >= 0.3.0-beta.2, < 0.3.6fixed 0.3.6
Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method al
- CVE-2025-11362Oct 7, 2025affected >= 0.3.0-beta.1, < 0.3.0-beta.17fixed 0.3.0-beta.17
Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that trigger