Allocation of Resources Without Limits or Throttling Affecting pdfmake package, versions <0.3.0-beta.17


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-PDFMAKE-10223297
  • published6 Oct 2025
  • disclosed29 Apr 2025
  • creditRyusei Ishikawa

Introduced: 29 Apr 2025

CVE-2025-11362  (opens in a new tab)
CWE-770  (opens in a new tab)
First added by Snyk

How to fix?

Upgrade pdfmake to version 0.3.0-beta.17 or higher.

Overview

pdfmake is a Client/server side PDF printing in pure JavaScript

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.

References

CVSS Base Scores

version 4.0
version 3.1