pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying a crafted PDF with a FlateDecode stream containing a decompression bomb. Attackers can upload a small compressed PDF that decompresses to hundreds of megabytes, exhausting memory and crashing the Node.js process or freezing browser tabs during PDF parsing.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-31 09:17
Updated : 2026-09-10 15:53
NVD link : CVE-2026-82864
Mitre link : CVE-2026-82864
CVE.ORG link : CVE-2026-82864
JSON object : View
Products Affected
No product.
CWE
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
