Disclosure summary
Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to overwrite stack memory when opening AESV3/R6 encrypted PDFs. Attackers can supply a password longer than 127 bytes through applications using the libpoppler, libpoppler-glib or C++ API to overflow the K1 and E buffers, crashing the process or corrupting memory.
Source-reported weakness categories
CWE-121
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107705
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
- NIST NVD record
- CVE Program record
- gitlab.freedesktop.org
- gitlab.freedesktop.org
- gitlab.freedesktop.org
- gitlab.freedesktop.org
- www.vulncheck.com
PUBLISHED 2026-10-08T16:17:35-04:00
MODIFIED 2026-10-08T17:35:53-04:00
INGESTED 2026-10-10T20:55:03-04:00