CVE-2026-16633

HIGHCVSS · not yet scored
—
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: —CVSS v2: —Exploit: None knownExposed services: Not assessed

A fix is available — apply it.

PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF

Impact

If PDF.js is used to load a malicious PDF, and PDF.js is configured with enableScripting set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.

Patches

Workarounds

Set enableScripting to false or set a CSP.

CVSS v3
—
EchelonGraph score
Not yet assessedNo source has published severity data for this CVE yet — no CVSS score from NVD or a CNA, no GitHub advisory, and it is not in CISA KEV. This is not a rating of zero; we cannot assess it yet.
EG Score
—
EG Risk
—
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

Published

August 6, 2026

Last Modified

August 6, 2026

Vendor Advisories for CVE-2026-16633(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Affected Packages

(1 across 1 ecosystem)
npm(1)
PackageVulnerable rangeFix by version rangeDependents
pdfjs-dist—
  • 5.6.83 up to 6.2.108: fixed in 6.2.108
—

Data Freshness Timeline

(refreshed 0× in last 7d / 1× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-09-30 22:59 UTCEG score recompute
  2. 2026-08-06 22:07 UTCEG score recompute

Frequently asked(3)

What is CVE-2026-16633?
CVE-2026-16633 is a high vulnerability published on August 6, 2026. PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF Impact If PDF.js is used to load a malicious PDF, and PDF.js is configured with enableScripting set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be…
When was CVE-2026-16633 disclosed?
CVE-2026-16633 was first published on August 6, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
How do I remediate CVE-2026-16633?
A fix for CVE-2026-16633 is available: update to the fixed version the vendor names in its advisory. The vendor advisories EchelonGraph has for CVE-2026-16633 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-16633

Explore →

Is Your Infrastructure Affected by CVE-2026-16633?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.