GHSA-rj3r-r7hh-jxfq

Suggest an improvement
Source
https://github.com/advisories/GHSA-rj3r-r7hh-jxfq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-rj3r-r7hh-jxfq/GHSA-rj3r-r7hh-jxfq.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-rj3r-r7hh-jxfq
Aliases
Downstream
CGA (34)
MINI (7)
Published
2025-10-07T06:31:12Z
Modified
2026-07-17T21:09:54Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding
Details

Versions of the package pdfmake from 0.3.0-beta.1 to before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-07T22:16:11Z",
    "nvd_published_at": "2025-10-07T05:15:33Z",
    "severity": "HIGH"
}
References

Affected packages

npm / pdfmake

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.3.0-beta.1
Fixed
0.3.0-beta.17

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-rj3r-r7hh-jxfq/GHSA-rj3r-r7hh-jxfq.json"