Threats Tagged 'ghsa-w9hm-4m3m-fxmm'
View all threats tagged with 'ghsa-w9hm-4m3m-fxmm'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-w9hm-4m3m-fxmm'
Click on any threat for detailed analysis and mitigation recommendations
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633 0 ngx-extended-pdf-viewer includes a forked version of Mozilla's pdf.js that is vulnerable to CVE-2026-16633. This vulnerability allows execution of attacker-controlled JavaScript when opening a malicious PDF, potentially impacting the hosting page. The default configuration reduces exposure compared to upstream pdf.js, but enabling XFA forms (enabled by default) still presents risk. A patch is available from version 29.0.0-rc.3, which backports the upstream fix. Workarounds include disabling XFA forms or applying a Content Security Policy to block inline scripts. Join the discussion | GCVE Database | 08/06/2026, 21:13:59 UTC Added: 08/07/2026, 05:57:18 UTC |
Showing 1 to 1 of 1 result