CVE-2026-26801 describes a high-severity Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5, allowing a remote attacker to obtain sensitive information. Rated CVSS 7.5, this vulnerability has a network attack vector and low complexity, requiring no user interaction, primarily impacting confidentiality. There is currently no evidence of active exploitation or public exploit code, and community discussion is minimal. A fix is available in pdfmake version 0.3.6, which introduces URL access policy controls and logs warnings for unconfigured server-side usage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.3.1, <= 0.3.5CPE matchmatch criteria | cpe:2.3:a:pdfmake:pdfmake:*:*:*:*:*:*:*:* | ||
0.3.0CPE matchmatch criteria | cpe:2.3:a:pdfmake:pdfmake:0.3.0:-:*:*:*:*:*:* | ||
0.3.0CPE matchmatch criteria | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta10:*:*:*:*:*:* | ||
0.3.0CPE matchmatch criteria | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta11:*:*:*:*:*:* | ||
0.3.0CPE matchmatch criteria | cpe:2.3:a:pdfmake:pdfmake:0.3.0:beta12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.