---
id: CVE-2025-11362
title: >-
  Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are
  vulnerable to Allocation of Resources Without Limits or Throttling via
  repeatedly redirect URL in file embedding
summary: >-
  Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are
  vulnerable to Allocation of Resources Without Limits or Throttling via
  repeatedly redirect URL in file embedding. An attacker can cause the
  application to cra…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
  - CWE-770
vendor: pdfmake
product: pdfmake
affected:
  - pdfmake = 0.3.0
published: '2025-10-07'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11362'
references:
  - url: >-
      https://github.com/bpampuch/pdfmake/commit/741169634bf07730e010cd77477b6cc038e846ed
    label: report@snyk.io
  - url: 'https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-14101887'
    label: report@snyk.io
  - url: 'https://security.snyk.io/vuln/SNYK-JS-PDFMAKE-10223297'
    label: report@snyk.io
tags:
  - nvd
epss: 0.00426
epssPercentile: 0.34149
ingestedAt: '2026-08-06T17:00:11.500Z'
---

## Overview

Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.

## Affected

- `pdfmake = 0.3.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
