CVE-2026-54080
CVE-2026-54080 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1325.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.9)
- EPSS exploit prediction: 0% (23rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1325
- Published:
- Last modified:
Description
veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a crafted Type 0 font /Encoding or /ToUnicode CMap stream can execute unbounded PostScript array allocation or a zero-increment for loop and exhaust validator memory or CPU. This issue is fixed in versions 1.30.2 and 1.31.23.
Frequently asked questions
- What is CVE-2026-54080?
- veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a crafted Type 0 font /Encoding or /ToUnicode CMap stream can execute unbounded PostScript array allocation or a zero-increment for loop and exhaust validator memory or CPU. This issue is fixed in versions 1.30.2 and 1.31.23.
- How severe is CVE-2026-54080?
- CVE-2026-54080 has a CVSS 4.0 base score of 6.9, rated medium severity.
- Is CVE-2026-54080 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (23rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-54080?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-54080 published?
- CVE-2026-54080 was published on 2026-07-29 and last updated on 2026-07-30.
References
- https://github.com/veraPDF/veraPDF-parser/commit/73d6ec002b98ce1f3f68640442f8e5d5613c80ce
- https://github.com/veraPDF/veraPDF-parser/commit/cb3538607a549d63504299be1088c85ae48605f4
- https://github.com/veraPDF/veraPDF-parser/pull/703
- https://github.com/veraPDF/veraPDF-parser/security/advisories/GHSA-jrmc-qg6p-94fp
Other CWE-1325 vulnerabilities
- CVE-2024-27796 — High (CVSS 7.8): The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS…
- CVE-2026-34183 — High (CVSS 7.5): Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing…
- CVE-2025-2240 — High (CVSS 7.5): A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This…
- CVE-2026-54081 — Medium (CVSS 6.9): veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a…
- CVE-2026-18772 — Medium (CVSS 6.5): Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data…
- CVE-2026-13056 — Medium (CVSS 6.5): Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate…