7.5
CVE-2026-26801
- EPSS 0.48%
- Veröffentlicht 10.03.2026 00:00:00
- Zuletzt bearbeitet 07.05.2026 20:32:39
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method allowing server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.376 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://github.com/bpampuch/pdfmake
https://github.com/bpampuch/pdfmake/blob/master/src/URLResolver.js
https://github.com/bpampuch/pdfmake/releases/tag/0.3.6
https://github.com/bpampuch/pdfmake/pull/2920
https://mariopepe.github.io/cve-2026-26801-pdfmake-ssrf