CVE-2026-25535: CWE-400: Uncontrolled Resource Consumption in parallax jsPDF
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the `addImage` method, a user can provide a harmful GIF file that results in out of memory errors and denial of service. Harmful GIF files have large width and/or height entries in their headers, which lead to excessive memory allocation. Other affected methods are: `html`. The vulnerability has been fixed in jsPDF 4.2.0. As a workaround, sanitize image data or URLs before passing it to the addImage method or one of the other affected methods.
AI Analysis
Technical Summary
CVE-2026-25535 is a high-severity vulnerability in the jsPDF JavaScript library (parallax project) affecting versions before 4.2.0. The vulnerability arises from insufficient validation of the first argument to the addImage method, allowing attackers to supply malicious GIF images with large width and/or height values. This causes excessive memory allocation, resulting in out-of-memory errors and denial of service. The html method is also affected by this uncontrolled resource consumption issue. The vulnerability is classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-770. The issue has been addressed and fixed in jsPDF version 4.2.0. Vendor advisories from Red Hat confirm the fix and recommend upgrading to patched versions.
Potential Impact
Exploitation of this vulnerability can cause denial of service by exhausting system memory when processing maliciously crafted GIF images via the addImage or html methods in jsPDF. This can disrupt applications relying on jsPDF for PDF generation, potentially causing crashes or unresponsiveness. There are no known exploits in the wild at this time.
Mitigation Recommendations
An official fix is available in jsPDF version 4.2.0. Users should upgrade to version 4.2.0 or later to remediate this vulnerability. As a temporary workaround, sanitize and validate all image data or URLs before passing them to the addImage or html methods to prevent malicious input from triggering excessive memory allocation.
CVE-2026-25535: CWE-400: Uncontrolled Resource Consumption in parallax jsPDF
Description
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the `addImage` method, a user can provide a harmful GIF file that results in out of memory errors and denial of service. Harmful GIF files have large width and/or height entries in their headers, which lead to excessive memory allocation. Other affected methods are: `html`. The vulnerability has been fixed in jsPDF 4.2.0. As a workaround, sanitize image data or URLs before passing it to the addImage method or one of the other affected methods.
CVSS v4.0
Score 8.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-25535 is a high-severity vulnerability in the jsPDF JavaScript library (parallax project) affecting versions before 4.2.0. The vulnerability arises from insufficient validation of the first argument to the addImage method, allowing attackers to supply malicious GIF images with large width and/or height values. This causes excessive memory allocation, resulting in out-of-memory errors and denial of service. The html method is also affected by this uncontrolled resource consumption issue. The vulnerability is classified under CWE-400 (Uncontrolled Resource Consumption) and CWE-770. The issue has been addressed and fixed in jsPDF version 4.2.0. Vendor advisories from Red Hat confirm the fix and recommend upgrading to patched versions.
Potential Impact
Exploitation of this vulnerability can cause denial of service by exhausting system memory when processing maliciously crafted GIF images via the addImage or html methods in jsPDF. This can disrupt applications relying on jsPDF for PDF generation, potentially causing crashes or unresponsiveness. There are no known exploits in the wild at this time.
Mitigation Recommendations
An official fix is available in jsPDF version 4.2.0. Users should upgrade to version 4.2.0 or later to remediate this vulnerability. As a temporary workaround, sanitize and validate all image data or URLs before passing them to the addImage or html methods to prevent malicious input from triggering excessive memory allocation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-02-02T19:59:47.374Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-25535","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7110","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7128","vendor":"Red Hat"}]
Threat ID: 6997264f521539184371324a
Added to database: 02/19/2026, 15:03:43 UTC
Last enriched: 07/22/2026, 22:42:31 UTC
Last updated: 07/27/2026, 08:52:01 UTC
Views: 563
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.