PT-2026-42033 · Setasign+2 · Fpdi+1
CVE-2026-45802
·
Published
2026-05-19
·
Updated
2026-06-11
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FPDI versions prior to 2.6.7
Description
FPDI is a collection of PHP classes used to read pages from existing PDF documents to serve as templates in FPDF. A Denial of Service (DoS) issue exists where an attacker can upload a small, malicious PDF file, causing the server-side script to crash. This occurs due to memory exhaustion or a script time-out, and repeated attacks can result in sustained service unavailability.
Recommendations
Update to version 2.6.7.
Exploit
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fpdi
Setasign/Fpdi