Back

MEDIUM

FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service

Published Jun 11, 2026

Description

FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2.6.7, an attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion or a script time-out. Repeated attacks can lead to sustained service unavailability. This issue has been patched in version 2.6.7.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 11, 2026
Updated Jun 12, 2026
Reserved May 13, 2026
CISA Vulnrichment
Updated Jun 12, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-2MGW-7Q6P-8GRG