OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-91941 (CVSS 8.7)

NVD · officialPublished Sep 15, 2026Risk 37/100EPSS 0.4%

Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and bandwidth on shared workers.

CVSS
8.7
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source