CVE-2026-91941: Crawl4AI before 0.9.3 Denial of Service via PDFContentScrapingStrategy

Published Sep 15, 2026
·
Updated

Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.

Affected Software

0 affected components

Event History

Sep 15, 2026
CVE Published
via MITRE·03:18 PM
Data Sourced
via MITRE·03:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this denial-of-service issue?

Deployments running Crawl4AI before 0.9.3 are exposed when untrusted clients can submit POST requests that select the PDF scraping strategy. Shared workers are particularly at risk because the downloaded PDFs can exhaust shared disk, CPU, and bandwidth resources.

2

What does an attacker need to exploit it?

An attacker needs network access to a POST request endpoint that accepts untrusted input and permits selection of PDFContentScrapingStrategy. No privileges or user interaction are required.

3

How can I tell whether my deployment is affected?

Check whether the Crawl4AI version is earlier than 0.9.3 and whether POST requests from untrusted clients can select the PDF scraping strategy. Such requests may cause workers to download large remote PDFs without size or page limits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203