CVE-2026-54080 Details
Description
veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a crafted Type 0 font /Encoding or /ToUnicode CMap stream can execute unbounded PostScript array allocation or a zero-increment for loop and exhaust validator memory or CPU. This issue is fixed in versions 1.30.2 and 1.31.23.
A denial-of-service vulnerability has been identified in veraPDF PDF parser versions prior to 1.30.2 and 1.31.23. The issue arises in the CMapParser and PSOperator classes, where a crafted Type 0 font's /Encoding or /ToUnicode CMap stream can trigger unbounded PostScript array allocations or zero-increment loops. This exploitation can lead to excessive memory or CPU usage, causing the validator to slow down or crash. The vulnerability is present because the CMap parser, which is used to interpret PostScript, does not properly validate certain operations before execution. As a result, an attacker can manipulate the PostScript processing to exhaust system resources,
Users can upgrade to veraPDF versions 1.30.2 or 1.31.23, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 29, 2026CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1325 | Improperly Controlled Sequential Memory Allocation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| veraPDF | <= 1.30.1 (semver) >= 1.31.1, <= 1.31.22 (semver) |
CPE
Remediation
| |
| veraPDF-parser | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | New CVE Received | [email protected] |
| Jul 29, 2026 | CVE Modified | CISA-ADP |
Volerion