CVE-2026-26801

EUVD-2026-10756
Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method allowing server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
Affected Products (NVD)
VendorProductVersion
pdfmakepdfmake
0.3.1 ≤
𝑥
≤ 0.3.5
pdfmakepdfmake
0.3.0
pdfmakepdfmake
0.3.0:beta10
pdfmakepdfmake
0.3.0:beta11
pdfmakepdfmake
0.3.0:beta12
pdfmakepdfmake
0.3.0:beta13
pdfmakepdfmake
0.3.0:beta14
pdfmakepdfmake
0.3.0:beta15
pdfmakepdfmake
0.3.0:beta16
pdfmakepdfmake
0.3.0:beta17
pdfmakepdfmake
0.3.0:beta18
pdfmakepdfmake
0.3.0:beta19
pdfmakepdfmake
0.3.0:beta2
pdfmakepdfmake
0.3.0:beta3
pdfmakepdfmake
0.3.0:beta4
pdfmakepdfmake
0.3.0:beta5
pdfmakepdfmake
0.3.0:beta6
pdfmakepdfmake
0.3.0:beta7
pdfmakepdfmake
0.3.0:beta8
pdfmakepdfmake
0.3.0:beta9
𝑥
= Vulnerable software versions