CVE-2026-54081
veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/type1/Type1FontProgram.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a crafted Type 1 font /FontDescriptor /FontFile program can execute unbounded PostScript array allocation, a zero-increment for loop, or self-recursive toExecute user dictionary lookups and exhaust validator memory, CPU, or stack. This issue is fixed in versions 1.30.2 and 1.31.23.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.30%
- CWE
- CWE-1325
- Published
- 2026-07-29
- Last modified
- 2026-07-30
Affected products
- veraPDF veraPDF-parser
- veraPDF veraPDF-parser
Weakness type
Related vulnerabilities
- CVE-2026-71436 — Mermaid XY Charts are vulnerable to an infinite loop DoS
- CVE-2026-18772 — Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized...
- CVE-2026-54080 — veraPDF Parser DoS via PostScript CMap Streams
- CVE-2026-13056 — A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM
- CVE-2026-34183 — Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
- CVE-2026-8199 — Post-auth memory exhaustion via bitwise match expressions
- CVE-2026-6535 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6533 — Improperly Controlled Sequential Memory Allocation in Wireshark