Description
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Crawl4AI before version 0.9.3 contains an uncontrolled resource consumption flaw in its PDFContentScrapingStrategy. Untrusted clients can trigger the download of arbitrarily large remote PDFs without limits on PDF size or number of pages, a malicious request can deplete disk space, consume excessive CPU cycles, and exhaust network bandwidth on shared workers, resulting in a denial of service. The weakness is an example of CWE-400.

Affected Systems

The affected product is Crawl4AI by unclecode. All releases prior to 0.9.3 are vulnerable. No specific sub‑versions are listed, so any installation of Crawl4AI before as at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score of less than 1% indicates a very low exploitation probability, and the issue is not currently listed in the CISA KEV catalog. Attack vectors are inferred to be remote, via HTTP POST requests to the PDF scraping endpoint. An attacker only requires the ability to send crafted requests to the service; no authentication is implied in the description. The exploit would lead to service disruption on affected hosts or shared worker environments that host Crawl4AI.

Generated by OpenCVE AI on September 20, 2026 at 16:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Crawl4AI to version 0.9.3 or later, which removes the uncontrolled resource consumption bug.
  • If upgrading is not immediately possible, configure the PDF scraping strategy to enforce hard limits on PDF size and page count to prevent unbounded resource use.
  • Restrict access to the PDF scraping endpoint by implementing network or application‑level access controls, and apply rate limiting to mitigate abuse.
  • Monitor disk, CPU, and bandwidth usage on workers running Crawl4AI and alert on abnormal spikes that may indicate exploitation.

Generated by OpenCVE AI on September 20, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Unclecode
Unclecode crawl4ai
Vendors & Products Unclecode
Unclecode crawl4ai

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
Title Crawl4AI before 0.9.3 Denial of Service via PDFContentScrapingStrategy
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Unclecode Crawl4ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-20T00:35:29.818Z

Reserved: 2026-09-15T11:07:01.912Z

Link: CVE-2026-91941

cve-icon Vulnrichment

Updated: 2026-09-20T00:30:30.496Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:46.000

Modified: 2026-09-20T01:16:33.873

Link: CVE-2026-91941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption