Skip to content
CVE-2026-91941 and CVE-2026-92177: Critical Vulnerabilities in PDF Processing Tools

CVE-2026-91941 and CVE-2026-92177: Critical Vulnerabilities in PDF Processing Tools

First seen 16 Sep 2026, 16:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 16:33 UTC
  • CVE-2026-91941 allows denial of service via large PDF downloads in Crawl4AI.
  • CVE-2026-92177 enables remote code execution in pdfforge PDF Architect with user interaction.
  • Both vulnerabilities were published on September 15, 2026, and require immediate attention.

Two critical vulnerabilities were disclosed on September 15, 2026, affecting PDF processing tools. CVE-2026-91941 in Crawl4AI allows attackers to exploit uncontrolled resource consumption, leading to denial of service through large PDF downloads. This affects internet-facing APIs and multi-tenant platforms, posing a high operational risk. CVE-2026-92177 in pdfforge PDF Architect enables remote code execution via out-of-bounds write vulnerabilities, requiring user interaction to exploit. Both vulnerabilities lack active exploitation evidence but should be addressed promptly. The potential impact includes service disruption and unauthorized code execution on affected systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-15
CVE-2026-91941 published
Crawl4AI vulnerability disclosed, allowing denial of service via uncontrolled resource consumption.
Redpacketsecurity
2026-09-15
CVE-2026-92177 published
pdfforge PDF Architect vulnerability disclosed, enabling remote code execution with user interaction.
Nvd.Nist
2026-09-16
Current status assessment
Both vulnerabilities are acknowledged but lack evidence of active exploitation as of today.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track Crawl4AI and CVE-2026-91941 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed