Unbounded Buffer Growth Vulnerability in pdfme PDF-Lib
CVE-2026-82864

7.1HIGH

Key Information:

Vendor

PDFme

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82864?

The pdfme pdf-lib up to version 5.5.10 is vulnerable to a denial-of-service attack through an unbounded buffer growth issue in the DecodeStream.ensureBuffer() method. Attackers can exploit this by crafting a malicious PDF that contains a FlateDecode stream leading to a decompression bomb. This allows the attacker to upload a deceptively small compressed PDF that expands to a significantly larger size, resulting in excessive memory consumption which can crash the Node.js process or freeze browser tabs during PDF processing. Users of affected versions are encouraged to update to mitigate possible threats.

Affected Version(s)

pdf-lib 0 < 5.5.10

pdf-lib 5.5.10

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.