Junglewise Threat Intelligence

CVE-2026-54080: veraPDF veraPDF-parser denial of service in PostScript CMap streams

CVE-2026-54080 · Severity: medium · CVSS 4 · Published 2026-07-29

Vendors: veraPDF.

Executive brief

veraPDF is a library used to validate that PDF files comply with archival standards. A vulnerability in its PDF parsing component allows a specially crafted PDF file to crash the software or freeze the system by exhausting its memory and processing power. This could be used to disrupt automated document processing workflows or cause a denial-of-service for services that rely on veraPDF for file validation.

Technical details

A denial-of-service vulnerability exists in the veraPDF-parser library due to improper resource management in its PostScript interpreter. Specifically, the CMapParser and PSOperator components fail to validate bounds for certain PostScript operators. An attacker can provide a PDF with a crafted Type 0 font /Encoding or /ToUnicode CMap stream that uses the 'array' operator to request a massive memory allocation (up to Integer.MAX_VALUE) or uses the 'for' operator with a zero-increment value to create an infinite loop. These actions lead to OutOfMemoryError or CPU exhaustion, crashing the validation worker. The issue is resolved in versions 1.30.2 and 1.31.23 by implementing limits on array sizes, loop iterations, and recursion depth.

Affected products

  • veraPDF veraPDF-parser < 1.30.2, >= 1.31.1, < 1.31.23

Timeline

  • 2026-05-19: other: Initial fix pull request submitted
  • 2026-05-29: patched: Fix merged into integration branch
  • 2026-06-08: advisory: GitHub Security Advisory published
  • 2026-07-29: disclosed: CVE published to NVD

References