CVE-2026-107705: Poppler 0.42.0 through 26.10.0 Stack Buffer Overflow via Decrypt::revision6Hash()

Published Oct 8, 2026
·
Updated

Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to overwrite stack memory when opening AESV3/R6 encrypted PDFs. Attackers can supply a password longer than 127 bytes through applications using the libpoppler, libpoppler-glib or C++ API to overflow the K1 and E buffers, crashing the process or corrupting memory.

Affected Software

1 affected component
Poppler Poppler>=0.42.0<=26.10.0

Event History

Oct 8, 2026
CVE Published
via MITRE·07:51 PM
Data Sourced
via MITRE·07:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications using libpoppler, libpoppler-glib, or the Poppler C++ API are exposed when they open AESV3/R6-encrypted PDFs and pass attacker-controlled passwords to the library.

2

What does an attacker need to trigger the overflow?

The attacker needs to control a password longer than 127 bytes supplied while opening an AESV3/R6-encrypted PDF. No authentication or user interaction is required according to the provided vector, but exploitation has high attack complexity.

3

What could happen if exploitation succeeds?

The overflow can overwrite the K1 and E stack buffers, causing the affected process to crash or corrupting its memory. The reported impact includes integrity and availability effects, with no confidentiality impact listed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203