{"id":"CVE-2026-77220","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-77220","summary":"PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without…","details":"PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data.","published":"2026-08-21T21:17:06.737","modified":"2026-08-21T21:17:06.737","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/michaelrsweet/pdfio/commit/22b9afc800c5833f9e851e35938972bd4c76a357","label":"michaelrsweet/pdfio@22b9afc"},"references":[{"type":"WEB","url":"https://github.com/michaelrsweet/pdfio/commit/22b9afc800c5833f9e851e35938972bd4c76a357"},{"type":"WEB","url":"https://github.com/michaelrsweet/pdfio/releases/tag/v1.6.5"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/pdfio-dangling-pointer-via-dictionary-string-formatting"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-21T21:17:06.737"}}