Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘 Packagist
Not in CISA KEV

GHSA-2mgw-7q6p-8grg — setasign/fpdi

Fix: Setasign/FPDI@1695cfc

GHSA-2mgw-7q6p-8grg is a Uncontrolled Resource Consumption vulnerability in setasign/fpdi. A fix is available for setasign/fpdi — see the affected versions and patch details below.

FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service

Also known asCVE-2026-45802
Published
May 19, 2026
Updated
Sep 10, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 30, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for GHSA-2mgw-7q6p-8grg.

EPSS Exploitation Probability

via FIRST.org ↗
0.5%probability of exploitation in next 30 days
Lower Risk+0.19%
Lower risk than most CVEs37th percentile — riskier than 37% of all scored CVEsHighest risk
0.00%0.32%0.63%0.95%0.3%0.3%0.5%Jul 26Sep 26Sep 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

1 pkg affected
🐘setasign/fpdi

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Impact

This is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion or a script time-out. Repeated attacks can lead to sustained service unavailability.

Patches

Fixed as of version 2.6.7

Workarounds

No.

References

No.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistsetasign/fpdiall versions2.6.7composer require setasign/fpdi:^2.6.7

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for setasign/fpdi, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update setasign/fpdi to 2.6.7 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-2mgw-7q6p-8grg is resolved across your whole dependency graph.

  3. Workarounds

    Cap what an attacker can consume: apply request size, rate and timeout limits in front of the affected component, and run it with memory and CPU limits so exhaustion degrades one worker rather than the whole service.

Frequently Asked Questions

### Impact This is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion or a script time-out. Repeated attacks can lead to sustained service unavailability. ### Patches Fixed as of version 2.6.7 ### Workarounds No. ### References No.
O3 Security · Impact-Aware SCA

Is GHSA-2mgw-7q6p-8grg in your dependencies?

Find it across Packagist, including transitive dependencies.

GHSA-2mgw-7q6p-8grg: setasign/fpdi DoS | O3 Security