{"id":"GHSA-95fx-jjr5-f39c","summary":"jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder","details":"### Impact\n\nUser control of the first argument of the `addImage` method results in Denial of Service.\n\nIf given the possibility to pass unsanitized image data or URLs to the `addImage` method, a user can provide a harmful BMP file that results in out of memory errors and denial of service. Harmful BMP files have large width and/or height entries in their headers, wich lead to excessive memory allocation.\n\nOther affected methods are: `html`.\n\nExample attack vector:\n\n```js\nimport { jsPDF } from \"jspdf\" \n\n// malicious BMP image data with large width/height headers\nconst payload = ...\n\nconst doc = new jsPDF();\n\ndoc.addImage(payload, \"BMP\", 0, 0, 100, 100);\n```\n\n### Patches\n\nThe vulnerability has been fixed in jsPDF 4.1.0. Upgrade to jspdf@\u003e=4.1.0.\n\n### Workarounds\n\nSanitize image data or URLs before passing it to the addImage method or one of the other affected methods.","aliases":["CVE-2026-24133"],"modified":"2026-09-10T03:50:34.569379842Z","published":"2026-02-02T18:29:13Z","database_specific":{"github_reviewed_at":"2026-02-02T18:29:13Z","nvd_published_at":"2026-02-02T23:16:08Z","cwe_ids":["CWE-20","CWE-400","CWE-770"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/parallax/jsPDF/security/advisories/GHSA-95fx-jjr5-f39c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24133"},{"type":"WEB","url":"https://github.com/parallax/jsPDF/commit/ae4b93f76d8fc1baa5614bd5fdb5d174c3b85f0d"},{"type":"PACKAGE","url":"https://github.com/parallax/jsPDF"},{"type":"WEB","url":"https://github.com/parallax/jsPDF/releases/tag/v4.1.0"}],"affected":[{"package":{"name":"jspdf","ecosystem":"npm","purl":"pkg:npm/jspdf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.1.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 4.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-95fx-jjr5-f39c/GHSA-95fx-jjr5-f39c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}