fpdf2 is vulnerable to Uncontrolled Resource Consumption
65
Medium Risk
fpdf2 expands SVG use references by deep-copying the entire referenced graphics tree on each reference. A small crafted SVG can nest use references so the number of in-memory objects grows exponentially during FPDF.image() processing. Rendering such input consumes excessive CPU and memory and can exhaust a PDF generation worker. The fix rejects reference cycles and excessive nested expansion and enforces configurable SVG complexity limits.
You are affected if you are using a version that falls within the vulnerable range and your application passes untrusted SVG data to FPDF.image().
fpdf2 is vulnerable to Uncontrolled Resource Consumption in versions 2.5.0 - 2.8.7.
Upgrade the fpdf2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant