Impact
Crawl4AI before version 0.9.3 contains an uncontrolled resource consumption flaw in its PDFContentScrapingStrategy. Untrusted clients can trigger the download of arbitrarily large remote PDFs without limits on PDF size or number of pages, a malicious request can deplete disk space, consume excessive CPU cycles, and exhaust network bandwidth on shared workers, resulting in a denial of service. The weakness is an example of CWE-400.
Affected Systems
The affected product is Crawl4AI by unclecode. All releases prior to 0.9.3 are vulnerable. No specific sub‑versions are listed, so any installation of Crawl4AI before as at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score of less than 1% indicates a very low exploitation probability, and the issue is not currently listed in the CISA KEV catalog. Attack vectors are inferred to be remote, via HTTP POST requests to the PDF scraping endpoint. An attacker only requires the ability to send crafted requests to the service; no authentication is implied in the description. The exploit would lead to service disruption on affected hosts or shared worker environments that host Crawl4AI.
OpenCVE Enrichment