FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
Description
Published to the GitHub Advisory Database
May 19, 2026
Reviewed
May 19, 2026
Published by the National Vulnerability Database
Jun 11, 2026
Last updated
Jun 12, 2026
Impact
This is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion or a script time-out. Repeated attacks can lead to sustained service unavailability.
Patches
Fixed as of version 2.6.7
Workarounds
No.
References
No.
References