CVE-2025-11362
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
07/10/2025
Last modified:
20/10/2025
Description
Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta10:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta11:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta12:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta13:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta14:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta15:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta16:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta4:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta5:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta6:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta7:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta8:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



