Uncontrolled Resource Consumption in Crawl4AI by Uncle Code
CVE-2026-91941
8.7HIGH
What is CVE-2026-91941?
The software Crawl4AI, prior to version 0.9.3, is susceptible to an uncontrolled resource consumption vulnerability within the PDFContentScrapingStrategy. This flaw allows untrusted clients to initiate denial of service attacks by selecting a PDF scraping strategy through POST requests. Attackers can exploit the system by downloading excessively large remote PDF files without any restrictions on size or page count, leading to the potential exhaustion of disk space, CPU resources, and bandwidth on shared worker services.
Affected Version(s)
crawl4ai 0 < 0.9.3
crawl4ai 0.9.3
