Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pdfme
Pdfme pdf-lib |
|
| Vendors & Products |
Pdfme
Pdfme pdf-lib |
Mon, 31 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 31 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying a crafted PDF with a FlateDecode stream containing a decompression bomb. Attackers can upload a small compressed PDF that decompresses to hundreds of megabytes, exhausting memory and crashing the Node.js process or freezing browser tabs during PDF parsing. | |
| Title | pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bomb | |
| First Time appeared |
Pdflib
Pdflib pdflib |
|
| Weaknesses | CWE-409 | |
| CPEs | cpe:2.3:a:pdflib:pdflib:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pdflib
Pdflib pdflib |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T18:51:47.171Z
Reserved: 2026-08-31T08:37:53.169Z
Link: CVE-2026-82864
Updated: 2026-08-31T16:23:11.410Z
Status : Received
Published: 2026-08-31T09:17:06.957
Modified: 2026-08-31T19:17:23.723
Link: CVE-2026-82864
No data.
OpenCVE Enrichment
Updated: 2026-08-31T21:21:51Z
