GCWing / GCWing/OpenBitFun

[Security]: RUSTSEC-2026-0187: lopdf 0.41.0 in Cargo.lock (stack overflow via deeply nested PDF objects)

Open
#2,586 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
2.2k
Forks
229
Avg merge
2h 46m
Merged PRs (30d)
577

Description

### Summary

`cargo audit` reports a vulnerability in the locked `lopdf` dependency:
RUSTSEC-2026-0187 (stack overflow when parsing deeply nested PDF
objects, CVSS 7.5). `Cargo.lock` on `main` pins `lopdf` 0.41.0, which is
within the affected range; the advisory is fixed in `lopdf` >= 0.42.0.

### Affected dependency chain

- `lopdf 0.41.0` (locked in `Cargo.lock`)
- pulled in by `pdf-inspector 0.1.7`, which is used by the anydoc
document-reading path (`pdf-inspector` declares `lopdf` and resolves
the vulnerable version)

### Reproduction (from a clean checkout)

1. `git clone` the repository and check out `main`.
2. Run `cargo audit` (or `cargo deny check advisories`).
3. Observed: `error[vulnerability]: Stack overflow in lopdf via deeply
nested PDF objects / lopdf 0.41.0` — exit code 1.

### Suggested fix

Upgrade `pdf-inspector` from 0.1.7 to 0.1.8, which raises its `lopdf`
requirement to >= 0.42.0 and resolves the advisory. No application
source changes are needed. I have a patch ready and will open a PR
referencing this issue.

Contributor guide

Open the contributing guide

Research direction

Start with Cargo.lock and reproduce the advisory using cargo audit or cargo deny check advisories. Check the pdf-inspector dependency in the anydoc document-reading path, then verify that the locked lopdf version is no longer affected and the advisory check passes.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
build-system, security
Issue type
Bug
Difficulty
1/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.