CVE-2025-11362: High severity Pdfmake Pdfmake vulnerability
Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
Other sources
Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
— MITRE
Versions of the package pdfmake from 0.3.0-beta.1 to before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/pdfmaketo a version that resolves this vulnerability.Fixed in 0.3.0-beta.17 - Upgrade
Upgrade
pdfmaketo a version that resolves this vulnerability.Fixed in 0.3.0-beta.17
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11362?
CVE-2025-11362 is categorized as a medium severity vulnerability.
How do I fix CVE-2025-11362?
To fix CVE-2025-11362, upgrade pdfmake to version 0.3.0-beta.17 or later.
What impact does CVE-2025-11362 have on my application?
CVE-2025-11362 can cause your application to crash or become unresponsive due to resource allocation issues.
Which versions of pdfmake are affected by CVE-2025-11362?
CVE-2025-11362 affects pdfmake versions before 0.3.0-beta.17.
Can an attacker exploit CVE-2025-11362 remotely?
Yes, an attacker can exploit CVE-2025-11362 remotely by providing crafted input that exploits the vulnerability.