THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-91941 (HIGH 7.5) — Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or

[NVD] CVE-2026-91941 (HIGH 7.5) — Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or

mednvdPublished 2026-09-15

CVE-2026-91941 CVSS: 7.5 HIGH Published: 2026-09-15T16:17:46.000

Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on sh

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-91941