PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-21 21:17
Updated : 2026-08-24 20:17
NVD link : CVE-2026-77220
Mitre link : CVE-2026-77220
CVE.ORG link : CVE-2026-77220
JSON object : View
Products Affected
No product.
CWE
CWE-825
Expired Pointer Dereference
