CVE-2026-25535Disclosure(parall / jspdf)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the `addImage` method, a user can provide a harmful GIF file that results in out of memory errors and denial of service. Harmful GIF files have large width and/or height entries in their headers, which lead to excessive memory allocation. Other affected methods are: `html`. The vulnerability has been fixed in jsPDF 4.2.0. As a workaround, sanitize image data or URLs before passing it to the addImage method or one of the other affected methods.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jspdf

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
jspdf

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-19: 2Technical Details · 2026-02-19: 202-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25535 jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given … https://www.cve.org/CVERecord?id=CVE-2026-25535

    Post summary

    CVE-2026-25535 is a denial‑of‑service vulnerability in jsPDF (before v4.2.0) caused by user-controlled addImage arguments; no PoC, exploit, or patch information is provided.

    1001191
    56.4K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25535: The 4GB GIF: Crashing Browsers and Servers with CVE-2026-25535 A logic flaw in jsPDF's bundled GIF parser allows attackers to trigger a massive memory allocation by manipulating image headers. By specifying a canvas size of 65535x65535... https://cvereports.com/reports/CVE-2026-25535

    Post summary

    The post announces CVE‑2026‑25535, detailing a logic flaw in jsPDF’s GIF parser that allows a massive memory allocation via crafted image headers, but it does not mention exploits, patches, or active attacks.

    0000135
    26 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appparalljspdf-node.js-

Explore more