GHSA-rj3r-r7hh-jxfq · Severity: high · Ecosystem: npm — pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding
Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
Conclusion & alert: CVE-2025-11362 is rated Moderate Risk (40.5/100): CVSS High severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-13 | 0.04% | 0.05% | +0.01% |
| 2 | 2025-10-07 | — | 0.04% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-rj3r-r7hh-jxfq · Severity: high · Ecosystem: npm — pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta1:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta10:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta11:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta12:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta13:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta14:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta15:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta16:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta2:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta3:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta4:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta5:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta6:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta7:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta8:*:*:*:*:*:* |
| pdfmake | pdfmake | 0.3.0 | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta9:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/bpampuch/pdfmake/commit/741169634bf07730e010cd77477b6cc038e846ed | Patch |
| https://security.snyk.io/vuln/SNYK-JS-PDFMAKE-10223297 | Third Party Advisory |