PatchSiren

podofo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM podofo CVE published 2026-09-17

CVE-2026-54633

CVE-2026-54633 is a medium-severity heap out-of-bounds read vulnerability in PoDoFo, a C++17 PDF manipulation library. The vulnerability affects versions 1.0.0 through 1.1.0 and can cause a crash or disclose adjacent heap data when processing a crafted PDF with an Indexed color-space image. Defenders responsible for systems using PoDoFo, particularly those processing PDF files from untrusted sources, shou [truncated]