CVE-2025-11362
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
07/10/2025
Last modified:
06/08/2026
Description
Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta10:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta11:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta12:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta13:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta14:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta15:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta16:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta4:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta5:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta6:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta7:*:*:*:*:*:* | ||
| cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta8:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



