Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 23 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Michaelrsweet
Michaelrsweet pdfio |
|
| Vendors & Products |
Michaelrsweet
Michaelrsweet pdfio |
Fri, 21 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data. | |
| Title | PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting | |
| Weaknesses | CWE-825 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T19:40:48.624Z
Reserved: 2026-08-20T18:25:46.943Z
Link: CVE-2026-77220
Updated: 2026-08-24T19:40:40.607Z
Status : Received
Published: 2026-08-21T21:17:06.737
Modified: 2026-08-24T20:17:20.537
Link: CVE-2026-77220
No data.
OpenCVE Enrichment
Updated: 2026-08-23T16:40:34Z