Description
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4199-1 | tcpdf security update |
Debian DSA |
DSA-5933-1 | tcpdf security update |
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 13 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tcpdf Project
Tcpdf Project tcpdf |
|
| CPEs | cpe:2.3:a:tcpdf_project:tcpdf:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tcpdf Project
Tcpdf Project tcpdf |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T19:29:22.901Z
Reserved: 2024-01-11T00:00:00.000Z
Link: CVE-2024-22641
Updated: 2025-11-03T19:29:22.901Z
Status : Modified
Published: 2024-05-28T21:16:29.337
Modified: 2025-11-03T20:16:09.483
Link: CVE-2024-22641
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA