CVE-2026-25535: jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions
Impact
User control of the first argument of the addImage method results in denial of service.
If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful GIF file that results in out of memory errors and denial of service. Harmful GIF files have large width and/or height entries in their headers, wich lead to excessive memory allocation.
Other affected methods are: html.
Example attack vector:
js import { jsPDF } from "jspdf"
// malicious GIF image data with large width/height headers const payload = ...
const doc = new jsPDF();
doc.addImage(payload, "GIF", 0, 0, 100, 100);
Patches
The vulnerability has been fixed in jsPDF 4.1.1. Upgrade to jspdf@>=4.2.0.
Workarounds
Sanitize image data or URLs before passing it to the addImage method or one of the other affected methods. References https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25535.md
Other sources
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the addImage method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the addImage method, a user can provide a harmful GIF file that results in out of memory errors and denial of service. Harmful GIF files have large width and/or height entries in their headers, which lead to excessive memory allocation. Other affected methods are: html. The vulnerability has been fixed in jsPDF 4.2.0. As a workaround, sanitize image data or URLs before passing it to the addImage method or one of the other affected methods.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/jspdfto a version that resolves this vulnerability.Fixed in 4.2.0 - Upgrade
Upgrade
jspdfto a version that resolves this vulnerability.Fixed in 4.2.0 - Configuration
Before calling jsPDF addImage(payload, "GIF", x, y, w, h) (and other affected methods, listed as `html`), sanitize the image data or URLs so that harmful GIFs with large width/height header values cannot be passed as unsanitized first arguments.
jsPDF Sanitize image data or URLs passed to addImage (and other affected methods) = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25535?
The severity of CVE-2026-25535 is classified as a denial of service vulnerability.
How do I fix CVE-2026-25535?
To fix CVE-2026-25535, update to a version of jsPDF that is 4.2.0 or later.
What software is affected by CVE-2026-25535?
CVE-2026-25535 affects versions of jsPDF up to 4.2.0.
What is the potential impact of CVE-2026-25535?
The potential impact of CVE-2026-25535 is user-controlled denial of service via the `addImage` method.
Can untrusted users exploit CVE-2026-25535?
Yes, untrusted users can exploit CVE-2026-25535 by passing unsanitized image data to the `addImage` method.