CVE-2025-11896

Published: October 16th, 2025
In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stack overflow.
Unknown
CVSS v2:

Status

DocFilters Release Package State Justification Comment
0.0.0.1 xpdf (4.05) Resolved Code Not Present Patched applied from about:blank
26.1.1 xpdf (4.05) Resolved Code Not Present Patched applied from about:blank
26.1 xpdf (4.05) Resolved Code Not Present Patched applied from about:blank
25.4 xpdf (4.05) Resolved Code Not Present Patched applied from about:blank
25.3 xpdf (4.05) Needs Triage
25.2 xpdf (4.05) Needs Triage
25.1.2 xpdf (4.05) Resolved Code Not Present Patched applied from about:blank
25.1.1 xpdf (4.05) Needs Triage
25.1 xpdf (4.05) Needs Triage
24.4 xpdf (4.05) Needs Triage
24.4.0 xpdf (4.05) Needs Triage
24.3 xpdf (4.05) Needs Triage
24.2.1 xpdf (4.05) Needs Triage
24.2 xpdf (4.05) Needs Triage
24.1 xpdf (3.02) Needs Triage
23.3 xpdf (3.02) Needs Triage
23.2.1 xpdf (3.02) Needs Triage
23.2 xpdf (3.02) Needs Triage
23.1 xpdf (3.02) Needs Triage

Severity score breakdown

References