Denial of Service Vulnerability in jsPDF Library by Parallax
CVE-2026-24133
What is CVE-2026-24133?
The jsPDF library, which facilitates PDF generation in JavaScript, contains a vulnerability affecting versions prior to 4.1.0. This issue arises from the user's ability to control the first argument of the addImage method, potentially leading to a denial-of-service condition. When unsanitized image data or URLs, specifically harmful BMP files with unusually large dimensions, are passed to the method, it triggers excessive memory allocation and subsequently results in out-of-memory errors. The vulnerability has been addressed in the latest version, jsPDF@4.1.0, which mitigates the threat by reinforcing input validation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
jsPDF < 4.1.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
