PT-2026-80361 · Go · Github.Com/Dslipak/Pdf+2
Publicado
2026-08-18
·
Atualizado
2026-08-18
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
(This report has been withdrawn with reason: "Report mistakenly added without having CVE / GHSA associated"). The PDF parser in rsc.io/pdf and its downstream forks github.com/ledongthuc/pdf and github.com/dslipak/pdf contains multiple defects when parsing untrusted input:
- Unchecked /Size, /Index, /W, and classic subsection header parameters in cross-reference tables allow crafted values to trigger fatal out-of-memory (OOM) panics.
- Unterminated hexadecimal strings cause an infinite loop in readByte and readHexString.
- Cyclic object references (/First, /Parent, /Kids, /Next) in document outlines cause unbounded recursion leading to uncatchable stack overflow.
- Various malformed constructs trigger runtime panics in NewReader and Page.Content (such as empty graphics state pop 'Q', oversized CMap entries, odd-length UTF-16 strings, and newline buffer underflows).
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Github.Com/Dslipak/Pdf
Github.Com/Ledongthuc/Pdf
Rsc.Io/Pdf