Description
Versions of the package pdfmake from 0.3.0-beta.1 to before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
Recommendation
Update the pdfmake package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.3.0-beta.1, < 0.3.0-beta.17
- Patched version(s): 0.3.0-beta.17
References
Could your website be exposed too?
SmartScanner can check your website for pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding and gives you actionable findings to investigate.
Start a free scanRelated Issues
- axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL - CVE-2025-27152
- Quill is vulnerable to XSS via HTML export feature - CVE-2025-15056
- Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data - CVE-2025-47204
- Fiora chat user avatar is vulnerable to XSS via SVG files - CVE-2025-56514


