What is CVE-2026-54080?
This vulnerability exists in older versions of the veraPDF PDF parser (prior to 1.30.2 and 1.31.23). A crafted PDF file can trigger a denial-of-service (DoS) condition in the `CMapParser.java` and `PSOperator.java` components. It is recommended to update the parser to the patched versions.
Azərbaycanca: Bu boşluq veraPDF PDF parser-in köhnə versiyalarında (1.30.2 və 1.31.23-dən əvvəl) aşkarlanmış zəiflikdir. Xüsusi hazırlanmış PDF faylı `CMapParser.java` və `PSOperator.java` komponentlərində denial-of-service (DoS) vəziyyətinə səbəb ola bilər. Təsirə məruz qalan sistemlərdə parser-i göstərilən versiyalara yeniləmək tövsiyə olunur.
FAQ2
Which components of veraPDF are affected by CVE-2026-54080?
This vulnerability affects the `CMapParser.java` and `PSOperator.java` components.
Which versions are recommended to update to for CVE-2026-54080?
It is recommended to update the parser to version 1.30.2 or 1.31.23 (or later).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.