Allocation of Resources Without Limits or Throttling in jspdf - CVE-2026-25535
Published: April 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the addImage and html methods when processing unsanitized GIF image data or URLs. A remote attacker can provide a crafted GIF file with large width or height header values to cause a denial of service.
The issue can trigger out-of-memory errors through excessive memory allocation.
Affected software
InfoSphere Optim Archive Viewer
How to mitigate CVE-2026-25535
InfoSphere Optim Archive Viewer - update to 11.7.0.14