CVE-2024-22641: Tcpdf Project Tcpdf

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

Affected products

Published 2024-05-28. Last modified 2026-06-17.