Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF …
High CVSS 7.5
Summary
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/unclecode/crawl4ai/security/advisories/GHSA-v2rm-hvrj-2x9q
- https://www.vulncheck.com/advisories/crawl4ai-before-0.9.3-denial-of-service-via-pdfcontentscrapingstrategy
Timeline
- nvd_ingest NVD