Vulnerability library
Security checkFebruary 19, 2026

jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmjspdf

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

User control of the first argument of the addImage method results in denial of service.

If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful GIF file that results in out of memory errors and denial of service.

Recommendation

Update the jspdf package to the latest compatible version. Followings are version details:

  • Affected version(s): < 4.2.0
  • Patched version(s): 4.2.0

References

Could your website be exposed too?

SmartScanner can check your website for jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated February 19, 2026