Infinite loop in jspdf - CVE-2025-57810
Published: August 27, 2025
Vulnerability identifier: #VU114450
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-57810
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the addImage method. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
jspdf
IBM Observability with Instana
Db2 Intelligence Center
DB2 Data Management Console
InfoSphere Optim Archive Viewer
IBM API Connect
Splunk Security Orchestration, Automation and Response (SOAR)
IBM Observability with Instana
Db2 Intelligence Center
DB2 Data Management Console
InfoSphere Optim Archive Viewer
IBM API Connect
Splunk Security Orchestration, Automation and Response (SOAR)
How to mitigate CVE-2025-57810
Install updates from vendor's website.
jspdf - update to 3.0.2
IBM Observability with Instana - update to 1.0.307
Db2 Intelligence Center - update to 1.1.2.0
DB2 Data Management Console - update to 3.1.13.2
IBM API Connect - update to 10.0.8.5
Splunk Security Orchestration, Automation and Response (SOAR) - update to 7.1.0
InfoSphere Optim Archive Viewer - update to 11.7 FixPack13
IBM Observability with Instana - update to 1.0.307
Db2 Intelligence Center - update to 1.1.2.0
DB2 Data Management Console - update to 3.1.13.2
IBM API Connect - update to 10.0.8.5
Splunk Security Orchestration, Automation and Response (SOAR) - update to 7.1.0
InfoSphere Optim Archive Viewer - update to 11.7 FixPack13
External References
Related Security Bulletins
- Denial of service in jspdf
- Multiple vulnerabilities in IBM Db2 Intelligence Center
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Splunk SOAR update for third-party components
- Multiple vulnerabilities in IBM Observability with Instana
- IBM InfoSphere Optim Archive Viewer update for jsPDF