CVE-2026-26801
EUVD-2026-1075610.03.2026, 19:17
Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method allowing server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pdfmake | pdfmake | 0.3.1 ≤ 𝑥 ≤ 0.3.5 |
| pdfmake | pdfmake | 0.3.0 |
| pdfmake | pdfmake | 0.3.0:beta10 |
| pdfmake | pdfmake | 0.3.0:beta11 |
| pdfmake | pdfmake | 0.3.0:beta12 |
| pdfmake | pdfmake | 0.3.0:beta13 |
| pdfmake | pdfmake | 0.3.0:beta14 |
| pdfmake | pdfmake | 0.3.0:beta15 |
| pdfmake | pdfmake | 0.3.0:beta16 |
| pdfmake | pdfmake | 0.3.0:beta17 |
| pdfmake | pdfmake | 0.3.0:beta18 |
| pdfmake | pdfmake | 0.3.0:beta19 |
| pdfmake | pdfmake | 0.3.0:beta2 |
| pdfmake | pdfmake | 0.3.0:beta3 |
| pdfmake | pdfmake | 0.3.0:beta4 |
| pdfmake | pdfmake | 0.3.0:beta5 |
| pdfmake | pdfmake | 0.3.0:beta6 |
| pdfmake | pdfmake | 0.3.0:beta7 |
| pdfmake | pdfmake | 0.3.0:beta8 |
| pdfmake | pdfmake | 0.3.0:beta9 |
𝑥
= Vulnerable software versions