Denial-of-Service Vulnerability in veraPDF PDF Parser by veraPDF
CVE-2026-54081

6.9MEDIUM

Key Information:

Vendor

VeraPDF

Vendor
CVE Published:
29 July 2026

What is CVE-2026-54081?

The veraPDF PDF parser has a vulnerability that allows an attacker to exploit crafted Type 1 font programs. This can lead to denial-of-service conditions through excessive resource consumption, such as memory, CPU, or stack exhaustion. The issue is addressed in the updates 1.30.2 and 1.31.23, which include fixes for issues within the Type1FontProgram and PSOperator classes.

Affected Version(s)

veraPDF-parser < 1.30.2 < 1.30.2

veraPDF-parser >= 1.31.1, < 1.31.23 < 1.31.1, 1.31.23

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.