Description
ngx-extended-pdf-viewer embeds a fork of Mozilla’s pdf.js rather than depending on pdfjs-dist, so this vulnerability is not visible to dependency scanners through package.json.
Recommendation
Update the ngx-extended-pdf-viewer package to the latest compatible version. Followings are version details:
- Affected version(s): >= 27.0.0-rc.0, < 29.0.0-rc.3
- Patched version(s): 29.0.0-rc.3
References
Could your website be exposed too?
SmartScanner can check your website for ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633 and gives you actionable findings to investigate.
Start a free scanRelated Issues
- survey-pdf Upgraded jsPDF Version Due to Security Vulnerability - CVE-2026-25630
- PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF - CVE-2026-16633
- Backstage vulnerable to potential reading of SCM URLs using built in token - CVE-2026-29185
- @sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sve - CVE-2026-22803


