CVE-2026-107705
Deferred Deferred - Pending Action

Stack-Based Buffer Overflow in Poppler PDF Library

Vulnerability report for CVE-2026-107705, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to overwrite stack memory when opening AESV3/R6 encrypted PDFs. Attackers can supply a password longer than 127 bytes through applications using the libpoppler, libpoppler-glib or C++ API to overflow the K1 and E buffers, crashing the process or corrupting memory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freedesktop poppler 0.42.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Poppler versions 0.42.0 through 26.10.0 have a stack-based buffer overflow in the Decrypt::revision6Hash() function. Attackers can exploit this by providing a password longer than 127 bytes when opening AESV3/R6 encrypted PDFs. This overflows the K1 and E buffers on the stack, potentially crashing the application or corrupting memory.

Detection Guidance

To detect this vulnerability, check the version of Poppler installed on your system. If it is between 0.42.0 and 26.10.0, it is vulnerable. Use commands like 'dpkg -l | grep poppler' on Debian-based systems or 'rpm -qa | grep poppler' on RPM-based systems to check the installed version.

Impact Analysis

If you open a malicious PDF with a specially crafted long password, the application using Poppler (like a PDF viewer or editor) could crash or execute arbitrary code. This may lead to denial of service, data corruption, or unauthorized access to your system depending on the application's context.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches if exploited, which may violate GDPR (data protection) or HIPAA (health information privacy) requirements. Organizations must ensure affected Poppler versions are patched to maintain compliance.

Mitigation Strategies

Update Poppler to a version beyond 26.10.0 to address the stack-based buffer overflow in Decrypt::revision6Hash(). Avoid opening PDFs with passwords longer than 127 bytes until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107705. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart