ZeroHour

CVE-2024-22641

PoC
CVSS 3.1
7.5 high
EPSS
1%p64
Published
()
Modified
Description

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

Vendors
tcpdf project
Products
tcpdf
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.