Executive brief
PDFME is a JavaScript library for PDF template generation and form handling used in both server-side and browser applications. An attacker can craft a malicious PDF with highly compressed (decompression bomb) FlateDecode streams that cause unbounded memory allocation when the library parses the PDF, leading to out-of-memory crashes and denial of service. A ~100KB compressed file can expand to >100MB during decompression, affecting both PDF generators and UI components that accept user-supplied templates.
Technical details
The vulnerability is a decompression bomb (zip bomb variant) caused by unbounded buffer growth in the DecodeStream.ensureBuffer() method. The method doubles its internal buffer size in a loop with no upper limit when decompressing FlateDecode streams. The vulnerable code path exists in packages/pdf-lib/src/core/streams/DecodeStream.ts:148-160, where size *= 2 continues indefinitely until memory exhaustion. An attacker-supplied PDF is loaded via the basePdf parameter in @pdfme/generator and @pdfme/ui, triggering full decompression through FlateStream → DecodeStream without size restrictions. The attack requires only the ability to supply a PDF template input and causes memory exhaustion in both Node.js server processes and browser tabs. Patches are available in version 5.5.10 and later.
Affected products
- PDFME @pdfme/pdf-lib <=5.5.9
- PDFME @pdfme/generator affected through @pdfme/pdf-lib dependency
- PDFME @pdfme/ui affected through @pdfme/pdf-lib dependency
Timeline
- 2026-03-20: disclosed: Vulnerability published on GitHub Advisory Database
- 2026-03-20: patched: Patched in @pdfme/pdf-lib version 5.5.10 and later