FPDI allows Memory Exhaustion (OOM) in PDF Parser which leads to Denial of Service
Description
Published to the GitHub Advisory Database
Aug 5, 2025
Reviewed
Aug 5, 2025
Published by the National Vulnerability Database
Aug 6, 2025
Last updated
Aug 6, 2025
Impact
This is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process
user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause
the server-side script to crash due to memory exhaustion. Repeated attacks can lead to sustained
service unavailability.
Patches
Fixed as of version 2.6.4
Workarounds
No.
References