PT-2026-42033 · Setasign+2 · Fpdi+1

CVE-2026-45802

·

Published

2026-05-19

·

Updated

2026-06-11

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FPDI versions prior to 2.6.7
Description FPDI is a collection of PHP classes used to read pages from existing PDF documents to serve as templates in FPDF. A Denial of Service (DoS) issue exists where an attacker can upload a small, malicious PDF file, causing the server-side script to crash. This occurs due to memory exhaustion or a script time-out, and repeated attacks can result in sustained service unavailability.
Recommendations Update to version 2.6.7.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45802
GHSA-2MGW-7Q6P-8GRG

Affected Products

Fpdi
Setasign/Fpdi