THREAT OPS › Threat News › [NVD] CVE-2026-91941 (HIGH 7.5) — Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or
[NVD] CVE-2026-91941 (HIGH 7.5) — Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or
CVE-2026-91941 CVSS: 7.5 HIGH Published: 2026-09-15T16:17:46.000
Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on sh
Indicators of compromise
- CVE-2026-91941cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-91941