Vulnerabilities
Vulnerable Software
Pdfmake:  >> Pdfmake  >> 0.3.0  Security Vulnerabilities
Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method allowing server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured.
CVSS Score
7.5
EPSS Score
0.0
Published
2026-03-10
Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
CVSS Score
8.7
EPSS Score
0.001
Published
2025-10-07


Contact Us

Shodan ® - All rights reserved