Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to overwrite stack memory when opening AESV3/R6 encrypted PDFs. Attackers can supply a password longer than 127 bytes through applications using the libpoppler, libpoppler-glib or C++ API to overflow the K1 and E buffers, crashing the process or corrupting memory. | |
| Title | Poppler 0.42.0 through 26.10.0 Stack Buffer Overflow via Decrypt::revision6Hash() | |
| First Time appeared |
Freedesktop
Freedesktop poppler |
|
| Weaknesses | CWE-121 | |
| CPEs | cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freedesktop
Freedesktop poppler |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T19:51:12.884Z
Reserved: 2026-10-08T16:52:24.550Z
Link: CVE-2026-107705
No data.
Status : Deferred
Published: 2026-10-08T20:17:35.300
Modified: 2026-10-08T21:35:53.890
Link: CVE-2026-107705
No data.
OpenCVE Enrichment
No data.