Infinite loop in jspdf - CVE-2025-57810

 

Infinite loop in jspdf - CVE-2025-57810

Published: August 27, 2025


Vulnerability identifier: #VU114450
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-57810
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the addImage method. A remote attacker can consume all available system resources and cause denial of service conditions.


Affected software

jspdf
IBM Observability with Instana
Db2 Intelligence Center
DB2 Data Management Console
InfoSphere Optim Archive Viewer
IBM API Connect
Splunk Security Orchestration, Automation and Response (SOAR)

How to mitigate CVE-2025-57810

Install updates from vendor's website.

jspdf - update to 3.0.2
IBM Observability with Instana - update to 1.0.307
Db2 Intelligence Center - update to 1.1.2.0
DB2 Data Management Console - update to 3.1.13.2
IBM API Connect - update to 10.0.8.5
Splunk Security Orchestration, Automation and Response (SOAR) - update to 7.1.0
InfoSphere Optim Archive Viewer - update to 11.7 FixPack13

External References

Related Security Bulletins