[Security]: RUSTSEC-2026-0187: lopdf 0.41.0 in Cargo.lock (stack overflow via deeply nested PDF objects)
- Vorherrschende Sprache
- Rust
- Sterne
- 2.2k
- Forks
- 229
- Ø Merge
- 2 Std. 46 Min.
- Gemergte PRs (30 T.)
- 577
Beschreibung
### Summary
`cargo audit` reports a vulnerability in the locked `lopdf` dependency:
RUSTSEC-2026-0187 (stack overflow when parsing deeply nested PDF
objects, CVSS 7.5). `Cargo.lock` on `main` pins `lopdf` 0.41.0, which is
within the affected range; the advisory is fixed in `lopdf` >= 0.42.0.
### Affected dependency chain
- `lopdf 0.41.0` (locked in `Cargo.lock`)
- pulled in by `pdf-inspector 0.1.7`, which is used by the anydoc
document-reading path (`pdf-inspector` declares `lopdf` and resolves
the vulnerable version)
### Reproduction (from a clean checkout)
1. `git clone` the repository and check out `main`.
2. Run `cargo audit` (or `cargo deny check advisories`).
3. Observed: `error[vulnerability]: Stack overflow in lopdf via deeply
nested PDF objects / lopdf 0.41.0` — exit code 1.
### Suggested fix
Upgrade `pdf-inspector` from 0.1.7 to 0.1.8, which raises its `lopdf`
requirement to >= 0.42.0 and resolves the advisory. No application
source changes are needed. I have a patch ready and will open a PR
referencing this issue.
Beitragsleitfaden
Rechercherichtung
Start with Cargo.lock and reproduce the advisory using cargo audit or cargo deny check advisories. Check the pdf-inspector dependency in the anydoc document-reading path, then verify that the locked lopdf version is no longer affected and the advisory check passes.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- rust
- Bereich
- build-system, security
- Issue-Typ
- Bug
- Schwierigkeit
- 1/5
- Geschätzter Aufwand
- 1-3 Stunden
- Aktivitätsstatus
- Aktiv
- Klarheit
- Klar beschrieben
- Anfängerfreundlichkeit
- 35/100