Denial of Service Vulnerability in FPDI by Setasign
CVE-2025-54869
6MEDIUM
What is CVE-2025-54869?
The FPDI library, used for reading pages from existing PDF documents, has a Denial of Service vulnerability in versions 2.6.2 and earlier. Attackers can exploit this vulnerability by uploading specially crafted malicious PDF files that cause memory exhaustion, potentially crashing server-side scripts. This can lead to extended service unavailability, making it critical for users of FPDI to update to version 2.6.3 or later to mitigate the risk.
Affected Version(s)
FPDI < 2.6.3
