Unbounded Buffer Growth Vulnerability in pdfme PDF-Lib
CVE-2026-82864
7.1HIGH
What is CVE-2026-82864?
The pdfme pdf-lib up to version 5.5.10 is vulnerable to a denial-of-service attack through an unbounded buffer growth issue in the DecodeStream.ensureBuffer() method. Attackers can exploit this by crafting a malicious PDF that contains a FlateDecode stream leading to a decompression bomb. This allows the attacker to upload a deceptively small compressed PDF that expands to a significantly larger size, resulting in excessive memory consumption which can crash the Node.js process or freeze browser tabs during PDF processing. Users of affected versions are encouraged to update to mitigate possible threats.
Affected Version(s)
pdf-lib 0 < 5.5.10
pdf-lib 5.5.10
