CVE-2026-107705: Poppler 0.42.0 through 26.10.0 Stack Buffer Overflow via Decrypt::revision6Hash()
Poppler 0.42.0 through 26.10.0 contains a stack-based buffer overflow in Decrypt::revision6Hash() that allows attackers controlling the password to overwrite stack memory when opening AESV3/R6 encrypted PDFs. Attackers can supply a password longer than 127 bytes through applications using the libpoppler, libpoppler-glib or C++ API to overflow the K1 and E buffers, crashing the process or corrupting memory.
Affected Software
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications using libpoppler, libpoppler-glib, or the Poppler C++ API are exposed when they open AESV3/R6-encrypted PDFs and pass attacker-controlled passwords to the library.
What does an attacker need to trigger the overflow?
The attacker needs to control a password longer than 127 bytes supplied while opening an AESV3/R6-encrypted PDF. No authentication or user interaction is required according to the provided vector, but exploitation has high attack complexity.
What could happen if exploitation succeeds?
The overflow can overwrite the K1 and E stack buffers, causing the affected process to crash or corrupting its memory. The reported impact includes integrity and availability effects, with no confidentiality impact listed.