CVE-2026-45802 — setasign/fpdi
Fix: Setasign/FPDI@1695cfcCVE-2026-45802 is a Uncontrolled Resource Consumption vulnerability in setasign/fpdi. A fix is available for setasign/fpdi — see the affected versions and patch details below.
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-45802.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
setasign/fpdiReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
Impact
This is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion or a script time-out. Repeated attacks can lead to sustained service unavailability.
Patches
Fixed as of version 2.6.7
Workarounds
No.
References
No.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | setasign/fpdi | all versions | 2.6.7composer require setasign/fpdi:^2.6.7 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for setasign/fpdi, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update setasign/fpdi to 2.6.7 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-45802 is resolved across your whole dependency graph.
Workarounds
Cap what an attacker can consume: apply request size, rate and timeout limits in front of the affected component, and run it with memory and CPU limits so exhaustion degrades one worker rather than the whole service.
Frequently Asked Questions
Is CVE-2026-45802 in your dependencies?
Find it across Packagist, including transitive dependencies.