Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-11362

Опубликовано: 07 окт. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta1:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta10:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta11:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta12:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta13:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta14:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta15:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta16:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta2:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta3:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta4:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta5:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta6:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta7:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta8:*:*:*:*:*:*
cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta9:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-770
CWE-770

Связанные уязвимости

CVSS3: 7.5
github
4 месяца назад

pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-770
CWE-770