CVE-2026-24133Disclosure(parall / jspdf)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch parall jspdf systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful BMP file that results in out of memory errors and denial of service. Harmful BMP files have large width and/or height entries in their headers, which lead to excessive memory allocation. The html method is also affected. The vulnerability has been fixed in [email protected].

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jspdf

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-09)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
jspdf

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-02: 1Mentions · 2026-02-03: 1Mentions · 2026-02-06: 1Mentions · 2026-02-09: 2Patch / Workaround · 2026-02-09: 2Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-09: 202-0202-0302-0602-09
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-021
Disclosure1
2026-02-031
Disclosure1
2026-02-061
General1
2026-02-092
Disclosure1Patch1
Full discourse5 posts
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    jsPDFにPDF注入とDoSの高リスクの脆弱性、緊急アップデート呼びかけ(CVE-2026-24737,CVE-2026-24133) https://rocket-boys.co.jp/security-measures-lab/high-risk-jspdf-vulnerabilities-enable-pdf-injection-and-dos-urgent-update-urged-cve-2026-24737-cve-2026-24133/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The article discloses high‑risk PDF injection and DoS vulnerabilities in jsPDF (CVE‑2026‑24737, CVE‑2026‑24133) and calls for an urgent update.

    01020161
    318 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    jsPDFにPDF注入とDoSの高リスクの脆弱性、緊急アップデート呼びかけ(CVE-2026-24737,CVE-2026-24133) https://rocket-boys.co.jp/security-measures-lab/high-risk-jspdf-vulnerabilities-enable-pdf-injection-and-dos-urgent-update-urged-cve-2026-24737-cve-2026-24133/

    Post summary

    The post announces high‑risk PDF injection and DoS vulnerabilities in jsPDF (CVE‑2026‑24737, CVE‑2026‑24133) and urges users to apply an urgent patch.

    0000063
    44 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about CVE-2026-24133 from https://vulntracker.io/cves/CVE-2026-24133 for FREE

    Post summary

    A tweet linking to a vulnerability detail page for CVE-2026-24133 without providing additional technical or exploit information.

    0000045
    333 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24133 Denial of Service via Malicious BMP Image in jsPDF Library Before 4.1.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24133

    Post summary

    A new CVE (CVE‑2026‑24133) is disclosed, describing a denial‑of‑service vulnerability triggered by malicious BMP images when using jsPDF libraries older than version 4.1.0; no patch or exploit evidence is provided.

    0000069
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24133 jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage method results in denial of service. If given th… https://www.cve.org/CVERecord?id=CVE-2026-24133

    Post summary

    The post reports a denial of service vulnerability in jsPDF’s addImage method before version 4.1.0, but provides no PoC, exploit details, patch information, or evidence of active exploitation.

    00000181
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparalljspdf-node.js-

Explore more