Intel

AIKIDO-2025-10508

PdfPig is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource Consumption Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

25

Low Risk

This Affects:

DOTNETPdfPig
0.1.10 - 0.1.10
Fixed in 0.1.11

TL;DR

Affected versions of this package are vulnerable to uncontrolled resource consumption due to maliciously crafted compressed input. When such input is decompressed, it can trigger excessive memory usage, potentially leading to out-of-memory (OOM) errors and application crashes. This vulnerability may be exploited to cause denial of service or disrupt system availability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

PdfPig is vulnerable to Uncontrolled Resource Consumption in versions 0.1.10 - 0.1.10.

How to fix this

Upgrade the PdfPig library to the patch version.