tecnickcom/tcpdf is vulnerable to Regular Expression Denial of Service (ReDoS)
31
Low Risk
Affected versions of this package are vulnerable to a Regular Expression Denial of Service (ReDoS) in the setSVGStyles function. A crafted input with patterns designed to trigger excessive backtracking in the regular expression can cause the function to consume excessive CPU resources, potentially leading to a denial of service.
You are affected if you are using a version that falls within the vulnerable range.
tecnickcom/tcpdf is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.0.000 - 6.7.6.
Upgrade the tecnickcom/tcpdf library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant