Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data. | |
| Title | PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting | |
| Weaknesses | CWE-825 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-21T20:54:34.762Z
Reserved: 2026-08-20T18:25:46.943Z
Link: CVE-2026-77220
No data.
Status : Received
Published: 2026-08-21T21:17:06.737
Modified: 2026-08-21T21:17:06.737
Link: CVE-2026-77220
No data.
OpenCVE Enrichment
No data.