{"id":"GHSA-2mgw-7q6p-8grg","summary":"FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service","details":"### Impact\nThis is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion or a script time-out. Repeated attacks can lead to sustained service unavailability.\n\n### Patches\nFixed as of version 2.6.7\n\n### Workarounds\nNo.\n\n### References\nNo.","aliases":["CVE-2026-45802"],"modified":"2026-09-10T03:51:04.134569546Z","published":"2026-05-19T19:56:17Z","database_specific":{"nvd_published_at":"2026-06-11T20:16:23Z","cwe_ids":["CWE-400","CWE-770"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-19T19:56:17Z"},"references":[{"type":"WEB","url":"https://github.com/Setasign/FPDI/security/advisories/GHSA-2mgw-7q6p-8grg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45802"},{"type":"WEB","url":"https://github.com/Setasign/FPDI/commit/1695cfcc7e01fe844a7296b3de90855a3fa65be6"},{"type":"PACKAGE","url":"https://github.com/Setasign/FPDI"},{"type":"WEB","url":"https://github.com/Setasign/FPDI/releases/tag/v2.6.7"}],"affected":[{"package":{"name":"setasign/fpdi","ecosystem":"Packagist","purl":"pkg:composer/setasign/fpdi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.7"}]}],"versions":["1.5.2","1.5.3","1.5.4","1.6.0","1.6.1","1.6.2","v2.0.0","v2.0.0-beta","v2.0.0-beta2","v2.0.0-rc1","v2.0.1","v2.0.2","v2.0.3","v2.1.0","v2.1.1","v2.2.0","v2.3.0","v2.3.1","v2.3.2","v2.3.3","v2.3.4","v2.3.5","v2.3.6","v2.3.7","v2.4.0","v2.4.1","v2.5.0","v2.6.0","v2.6.1","v2.6.2","v2.6.3","v2.6.4","v2.6.5","v2.6.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-2mgw-7q6p-8grg/GHSA-2mgw-7q6p-8grg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}