Intel

AIKIDO-2024-10398

tecnickcom/tcpdf is vulnerable to Regular Expression Denial of Service (ReDoS)

Regular Expression Denial of Service (ReDoS)CVE-2024-22641

31

Low Risk

This Affects:

phptecnickcom/tcpdf
2.0.000 - 6.7.6
Fixed in 6.7.7

TL;DR

Affected versions of this package are vulnerable to a Regular Expression Denial of Service (ReDoS) in the setSVGStyles function. A crafted input with patterns designed to trigger excessive backtracking in the regular expression can cause the function to consume excessive CPU resources, potentially leading to a denial of service.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

tecnickcom/tcpdf is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.0.000 - 6.7.6.

How to fix this

Upgrade the tecnickcom/tcpdf library to the patch version.