spring-ai-pdf-document-reader is vulnerable to Denial of Service (DoS)
75
High Risk
spring-ai-pdf-document-reader recursively walks a PDF outline tree during ingestion. A PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError on the ingestion thread. That stops document processing and can take down the worker. The patch bounds outline traversal so crafted PDFs no longer crash the reader.
You are affected if you are using a version that falls within the vulnerable range and you ingest PDFs with spring-ai-pdf-document-reader.
spring-ai-pdf-document-reader is vulnerable to Denial of Service (DoS) in versions 1.0.0 - 2.0.0.
Upgrade the org.springframework.ai:spring-ai-pdf-document-reader library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant