GCWing / GCWing/OpenBitFun

[Security]: RUSTSEC-2026-0187: lopdf 0.41.0 in Cargo.lock (stack overflow via deeply nested PDF objects)

Offen
#2,586 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Rust
Sterne
2.2k
Forks
229
Ø Merge
2 Std. 46 Min.
Gemergte PRs (30 T.)
577

Beschreibung

### Summary

`cargo audit` reports a vulnerability in the locked `lopdf` dependency:
RUSTSEC-2026-0187 (stack overflow when parsing deeply nested PDF
objects, CVSS 7.5). `Cargo.lock` on `main` pins `lopdf` 0.41.0, which is
within the affected range; the advisory is fixed in `lopdf` >= 0.42.0.

### Affected dependency chain

- `lopdf 0.41.0` (locked in `Cargo.lock`)
- pulled in by `pdf-inspector 0.1.7`, which is used by the anydoc
document-reading path (`pdf-inspector` declares `lopdf` and resolves
the vulnerable version)

### Reproduction (from a clean checkout)

1. `git clone` the repository and check out `main`.
2. Run `cargo audit` (or `cargo deny check advisories`).
3. Observed: `error[vulnerability]: Stack overflow in lopdf via deeply
nested PDF objects / lopdf 0.41.0` — exit code 1.

### Suggested fix

Upgrade `pdf-inspector` from 0.1.7 to 0.1.8, which raises its `lopdf`
requirement to >= 0.42.0 and resolves the advisory. No application
source changes are needed. I have a patch ready and will open a PR
referencing this issue.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start with Cargo.lock and reproduce the advisory using cargo audit or cargo deny check advisories. Check the pdf-inspector dependency in the anydoc document-reading path, then verify that the locked lopdf version is no longer affected and the advisory check passes.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
rust
Bereich
build-system, security
Issue-Typ
Bug
Schwierigkeit
1/5
Geschätzter Aufwand
1-3 Stunden
Aktivitätsstatus
Aktiv
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.