(This report has been withdrawn with reason: "Report mistakenly added without having CVE / GHSA associated"). The PDF parser in rsc.io/pdf and its downstream forks github.com/ledongthuc/pdf and github.com/dslipak/pdf contains multiple defects when parsing untrusted input:
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-6115"
}