bentopdf vulnerabilities
CVEs whose affected-version data names the bentopdf package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-77581High· 8.6PoCBentoPDF is a client-side PDF toolkit that is self hostable
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS proxy in cloudflare/cors-proxy-worker.js uses isPrivateOrReservedHost() to validate a supplied hostname separately from…
▾ Midnightalam00000 · bentopdfvia NVD
CVE-2026-63630Low· 3.4BentoPDF is a client-side PDF toolkit that is self hostable
BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without schema or destination validation. When a user imports the cra…
▾ Sunlitalam00000 · bentopdfvia NVD