Pdfmake is a client and server-side JavaScript library for PDF document generation that is embedded in web applications and Node.js services, where its vulnerability surface reflects the parsing and resource-handling demands of a document-generation engine. The observed weakness classes—including unthrottled resource allocation, code injection, and server-side request forgery—are characteristic of libraries that process user-supplied input to dynamically construct output documents. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pdfmake over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11362HIGH Versions of the package pdfmake before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attack | Oct 7, 2025 | 7.5 | 26 | NO | NO |
CVE-2026-26801HIGH Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js | Mar 10, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-25180CRITICAL An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the | Feb 29, 2024 | 9.8 | 25 | NO | NO |
CVE-2022-46161CRITICAL pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. | Dec 6, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pdfmake.
Media articles that mention a CVE ID that affects a product developed by Pdfmake — matched by CVE ID, not by vendor name.