CVE-2026-91941: Uncontrolled Resource Consumption in unclecode crawl4ai
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
AI Analysis
Technical Summary
The vulnerability CVE-2026-91941 affects crawl4ai versions prior to 0.9.3. It arises from the PDFContentScrapingStrategy allowing untrusted clients to specify PDF scraping in POST requests without restrictions on PDF size or page count. This lack of limits enables attackers to download large remote PDFs, leading to uncontrolled consumption of system resources such as disk, CPU, and bandwidth, resulting in denial of service conditions on shared worker environments.
Potential Impact
Successful exploitation allows remote attackers to cause denial of service by exhausting disk space, CPU, and bandwidth on shared workers running vulnerable versions of crawl4ai. This can disrupt service availability and degrade performance for legitimate users.
Mitigation Recommendations
Upgrade crawl4ai to version 0.9.3 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated in the provided data.
CVE-2026-91941: Uncontrolled Resource Consumption in unclecode crawl4ai
Description
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
CVSS v4.0
Score 8.7high
Affected software
unclecode
crawl4ai
pkg:github/unclecode/crawl4aiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-91941 affects crawl4ai versions prior to 0.9.3. It arises from the PDFContentScrapingStrategy allowing untrusted clients to specify PDF scraping in POST requests without restrictions on PDF size or page count. This lack of limits enables attackers to download large remote PDFs, leading to uncontrolled consumption of system resources such as disk, CPU, and bandwidth, resulting in denial of service conditions on shared worker environments.
Potential Impact
Successful exploitation allows remote attackers to cause denial of service by exhausting disk space, CPU, and bandwidth on shared workers running vulnerable versions of crawl4ai. This can disrupt service availability and degrade performance for legitimate users.
Mitigation Recommendations
Upgrade crawl4ai to version 0.9.3 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated in the provided data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-15T11:07:01.912Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa9651a55bf5e2cf502eb06
Added to database: 09/15/2026, 15:32:42 UTC
Last enriched: 09/15/2026, 16:01:44 UTC
Last updated: 09/16/2026, 02:32:14 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.