tecnickcom/tcpdf is vulnerable to Regular Expression Denial of Service (ReDoS)
31
Low Risk
Affected versions of this package are vulnerable to a Regular Expression Denial of Service (ReDoS) in the setSVGStyles function. A crafted input with patterns designed to trigger excessive backtracking in the regular expression can cause the function to consume excessive CPU resources, potentially leading to a denial of service.
You are affected if you are using a version that falls within the vulnerable range.
tecnickcom/tcpdf is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.0.000 - 6.7.6.
Upgrade the tecnickcom/tcpdf library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant