OSV-2026-504

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/poppler/OSV-2026-504.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2026-504
Published
2026-04-02T00:16:28.228723Z
Modified
2026-04-02T00:16:28.229037Z
Summary
Heap-use-after-free in ObjectStream::getObject
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=498251261

Crash type: Heap-use-after-free READ 4
Crash state:
ObjectStream::getObject
XRef::fetch
XRef::fetch
References

Affected packages

OSS-Fuzz / poppler

Package

Name
poppler
Purl
pkg:generic/poppler

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/poppler/poppler.git
Events

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/poppler/OSV-2026-504.yaml"
introduced_range
"304290044b5c6b1af62c3b44afa9fd674a9656af:1420107810fc928962c559ebf59cf110c5d3f7de"