ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
- Severity:
- High
Description
ngx-extended-pdf-viewer embeds a fork of Mozilla’s pdf.js rather than depending on pdfjs-dist, so this vulnerability is not visible to dependency scanners through package.json.
Recommendation
Update the ngx-extended-pdf-viewer package to the latest compatible version. Followings are version details:
- Affected version(s): >= 27.0.0-rc.0, < 29.0.0-rc.3
- Patched version(s): 29.0.0-rc.3
References
Related Issues
- survey-pdf Upgraded jsPDF Version Due to Security Vulnerability - CVE-2026-25630
- PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF - CVE-2026-16633
- Backstage vulnerable to potential reading of SCM URLs using built in token - CVE-2026-29185
- @sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sve - CVE-2026-22803
You might also like:
- Tags:
- npm
- ngx-extended-pdf-viewer
Anything's wrong? Let us know Last updated on August 06, 2026


