GHSA-jrmc-qg6p-94fp

Suggest an improvement
Source
https://github.com/advisories/GHSA-jrmc-qg6p-94fp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jrmc-qg6p-94fp/GHSA-jrmc-qg6p-94fp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jrmc-qg6p-94fp
Aliases
Published
2026-07-29T15:17:32Z
Modified
2026-07-29T15:30:39.625724805Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
veraPDF Parser DoS via PostScript CMap Streams
Details

Summary

Description

A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 0 font /Encoding (or any /ToUnicode) is a CMap stream containing attacker-supplied PostScript. veraPDF reuses its CMap parser as a general PostScript interpreter and exposes the unguarded array N allocation operator and the for control operator with no zero-increment guard. This affects all current versions of veraPDF-parser.

Details

The vulnerability resides in veraPDF-parser. CMap streams referenced as a Type 0 font's /Encoding (or any font's /ToUnicode) are parsed by CMapParser (veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java), which extends PSParser. Tokens that are not the small CMap-specific keyword set (begincodespacerange, bfchar, cidchar, ...) fall through to PSObject.execute (veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSObject.java), which dispatches generic PostScript operators implemented in PSOperator (veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java).

Two operators in that interpreter take their bound from the PDF and apply no validation: 1. array at PSOperator.java:536-547 pops the top number from the operand stack and immediately calls COSArray.construct(arraySize), then loops arraySize times appending COSObject.getEmpty(). COSArray.construct(int) calls new ArrayList<>(arraySize) (COSArray.java:102), so the underlying Object[] is allocated up-front. Passing 2147483647 (Integer.MAX_VALUE) requests a 16 GB backing array on a 64-bit JVM. 2. for at PSOperator.java:571-592 reads initial, increment, and limit from the stack and loops for (long i = initial; i <= limit; i += increment). Because increment is unchecked, 0 0 1 { } for produces an infinite-CPU spin (and progressively a heap exhaustion as each iteration pushes i onto the operand stack).

CMapFactory.getCMap only catches IOException and PostScriptException; it does not catch OutOfMemoryError or wall-clock budget, so the failure propagates out of font model construction and aborts the validation worker.

A single payload byte sequence, the unframed PostScript 2147483647 array, is sufficient. No begincmap/endcmap framing is required because the operator runs before the parser ever reaches the CMap structure.

Impact

This impacts all current releases of the veraPDF-parser. Successful exploitation requires only that the target validate an attacker-supplied PDF; a single Type 0 font with a malicious /Encoding (or any /ToUnicode) stream is sufficient.

Proposed Patch

Cap array allocation and forbid zero increments in for.

As a defensive measure, also wrap CMapFactory.getCMap to enforce a wall-clock and operand-stack-size budget on CMap parsing, and audit the remaining unbounded operators (copy, roll, dict) for similar primitives.

Database specific
{
    "cwe_ids": [
        "CWE-1325"
    ],
    "github_reviewed_at": "2026-07-29T15:17:32Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "nvd_published_at": null
}
References

Affected packages

Maven / org.verapdf:parser

Package

Name
org.verapdf:parser
View open source insights on deps.dev
Purl
pkg:maven/org.verapdf/parser

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.30.2

Affected versions

1.*
1.4.1
1.4.2
1.4.3
1.6.1
1.8.1
1.10.1
1.10.2
1.10.3
1.10.4
1.12.1
1.14.1-RC
1.14.1
1.14.2-RC
1.14.3-RC
1.14.4-RC
1.14.5-RC
1.14.6-RC
1.14.7-RC
1.14.9-RC
1.14.10-RC
1.14.11-RC
1.14.100
1.14.101
1.14.102
1.14.103
1.14.104
1.16.1
1.18.1
1.18.2
1.20.1
1.22.1
1.24.1
1.26.1
1.28.1
1.28.2
1.30.1

Database specific

last_known_affected_version_range
"<= 1.30.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jrmc-qg6p-94fp/GHSA-jrmc-qg6p-94fp.json"

Maven / org.verapdf:parser

Package

Name
org.verapdf:parser
View open source insights on deps.dev
Purl
pkg:maven/org.verapdf/parser

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.31.1
Fixed
1.31.23

Database specific

last_known_affected_version_range
"<= 1.31.22"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jrmc-qg6p-94fp/GHSA-jrmc-qg6p-94fp.json"