PT-2024-19516 · Tcpdf+2 · Tcpdf+2
Zunak
·
Published
2024-04-19
·
Updated
2025-08-21
·
CVE-2024-22640
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
TCPDF versions <= 6.6.5
Description
The issue concerns a ReDoS (Regular Expression Denial of Service) vulnerability that occurs when parsing an untrusted HTML page with a crafted color. This can lead to a denial of service.
Recommendations
For TCPDF versions <= 6.6.5, as a temporary workaround, consider avoiding the parsing of untrusted HTML pages until a patch is available. Restrict access to the HTML parsing functionality to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Red Os
Tcpdf