Uncontrolled Resource Consumption in Crawl4AI by Uncle Code
CVE-2026-91941

8.7HIGH

Key Information:

Vendor

Unclecode

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-91941?

The software Crawl4AI, prior to version 0.9.3, is susceptible to an uncontrolled resource consumption vulnerability within the PDFContentScrapingStrategy. This flaw allows untrusted clients to initiate denial of service attacks by selecting a PDF scraping strategy through POST requests. Attackers can exploit the system by downloading excessively large remote PDF files without any restrictions on size or page count, leading to the potential exhaustion of disk space, CPU resources, and bandwidth on shared worker services.

Affected Version(s)

crawl4ai 0 < 0.9.3

crawl4ai 0.9.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

c240030
.