Description
PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a heap out-of-bounds read in PdfColorSpaceFilterIndexed::FetchScanLine in src/podofo/main/PdfColorSpaceFilter.cpp. PODOFO_INVARIANT does not perform a runtime check, so a pixel index greater than or equal to m_MapSize can address beyond m_lookup. PdfColorSpaceFilterFactory::TryCreateFromObject also validates hival with an incorrect conjunction and no upper bound, allowing malformed Indexed color-space metadata outside the expected range. The resulting read can disclose adjacent heap data or crash the processing application. This issue is fixed in version 1.1.1.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read leading to potential data disclosure or denial of service
Action: Immediate Patch
AI Analysis

Impact

PoDoFo versions 1.0.0 through 1.1.1 contain a flaw in the handling of Indexed color‑space images that allows a heap out‑of‑bounds read in PdfColorSpaceFilterIndexed::FetchScanLine. The code fails to perform a runtime bounds check on pixel indices, allowing an attacker to craft a PDF with an image whose pixel index equals or exceeds the map size, causing the library to read beyond the bounds of the lookup table. This can expose adjacent heap data or trigger a crash, thereby enabling information disclosure or denial of service but not arbitrary code execution.

Affected Systems

The vulnerable product is the PoDoFo C++17 PDF manipulation library supplied by podofo:podofo. All releases from version 1.0.0 up to and including 1.1.1 are impacted. Version 1.1.1 contains the fix that removes the unchecked index usage and corrects the validation of Indexed color‑space metadata.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% shows that exploitation is currently rare; the vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the flaw by supplying a specially crafted PDF to any application that processes PDFs with PoDoFo; if the application accepts user‑supplied files from the internet or a shared network location, the vector could be remote, otherwise local. The impact is limited to information disclosure or an application crash, but it remains a concern for systems that process untrusted PDF files.

Generated by OpenCVE AI on September 19, 2026 at 02:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PoDoFo to version 1.1.1 or later, which fixes the out‑of‑bounds read and corrects metadata validation.
  • If an upgrade cannot be performed immediately, limit the PDF input to trusted sources and run the application in a restricted environment or sandbox to contain any memory disclosure or crash.
  • Continuously monitor for vendor notifications and apply the update as soon as possible to eliminate the vulnerability.

Generated by OpenCVE AI on September 19, 2026 at 02:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Podofo
Podofo podofo
Vendors & Products Podofo
Podofo podofo

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed color-space image can cause a heap out-of-bounds read in PdfColorSpaceFilterIndexed::FetchScanLine in src/podofo/main/PdfColorSpaceFilter.cpp. PODOFO_INVARIANT does not perform a runtime check, so a pixel index greater than or equal to m_MapSize can address beyond m_lookup. PdfColorSpaceFilterFactory::TryCreateFromObject also validates hival with an incorrect conjunction and no upper bound, allowing malformed Indexed color-space metadata outside the expected range. The resulting read can disclose adjacent heap data or crash the processing application. This issue is fixed in version 1.1.1.
Title PoDoFo: Heap Out-of-Bounds Read in Indexed Color Space Image Decoding (FetchScanLine)
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T01:52:46.723Z

Reserved: 2026-06-15T20:07:02.185Z

Link: CVE-2026-54633

cve-icon Vulnrichment

Updated: 2026-09-22T01:52:42.547Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T22:17:01.693

Modified: 2026-09-24T21:16:28.120

Link: CVE-2026-54633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:15:17Z

Weaknesses