PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-91941 unclecode CVE debrief

CVE-2026-91941 is a high-severity vulnerability in Crawl4AI before version 0.9.3, allowing untrusted clients to cause denial of service through the PDFContentScrapingStrategy. Attackers can exploit this by selecting the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, leading to exhaustion of disk, CPU, and bandwidth on shared workers.

Vendor
unclecode
Product
crawl4ai
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-15
Original CVE updated
2026-09-20
Advisory published
2026-09-15
Advisory updated
2026-09-20

Who should care

Defenders responsible for Crawl4AI instances, especially those exposed to untrusted clients, should assess exposure and take immediate action to update to version 0.9.3 or apply compensating controls.

Why it matters

CVE-2026-91941 is a high-severity vulnerability in Crawl4AI that allows denial of service through resource exhaustion. Defenders should verify exposure, update to version 0.9.3, and apply compensing controls.

  • Denial of service through resource exhaustion
  • Potential disruption of services relying on Crawl4AI
  • Need for verification of Crawl4AI version and exposure
  • Potential impact on shared worker resources

Technical summary

The vulnerability is caused by an uncontrolled resource consumption issue in the PDFContentScrapingStrategy of Crawl4AI before version 0.9.3. This allows attackers to download large remote PDFs without size or page limits, leading to exhaustion of disk, CPU, and bandwidth on shared workers. Defenders should verify exposure of Crawl4AI instances, especially those exposed to untrusted clients, and assess the version of Crawl4AI in use. Immediate action is required to update to version 0.9.3 or apply compensating controls to limit the impact of potential attacks. The CVE record and NVD entry provide details about the vulnerability, including its description and CVSS score.

Defensive priority

Defenders should prioritize verifying exposure of Crawl4AI instances, especially those exposed to untrusted clients, and assess the version of Crawl4AI in use. Immediate action is required to update to version 0.9.3 or apply compensating controls to limit the impact of potential attacks.

Recommended defensive actions

  • Verify the version of Crawl4AI in use and update to version 0.9.3 or later
  • Assess exposure of Crawl4AI instances, especially those exposed to untrusted clients
  • Apply compensating controls to limit the impact of potential attacks
  • Monitor for potential exploitation attempts
  • Review relevant logs for exposed assets that need extra review
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, including its description and CVSS score. However, the exact scope of affected versions and potential exploitation remains limited, requiring further verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-91941 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-91941

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-91941 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91941

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.