[Security]: RUSTSEC-2026-0187: lopdf 0.41.0 in Cargo.lock (stack overflow via deeply nested PDF objects)
- Langage dominant
- Rust
- Étoiles
- 2.3k
- Forks
- 231
- Merge moyen
- 2 h 46 min
- PR mergées (30 j)
- 577
Description
### Summary
`cargo audit` reports a vulnerability in the locked `lopdf` dependency:
RUSTSEC-2026-0187 (stack overflow when parsing deeply nested PDF
objects, CVSS 7.5). `Cargo.lock` on `main` pins `lopdf` 0.41.0, which is
within the affected range; the advisory is fixed in `lopdf` >= 0.42.0.
### Affected dependency chain
- `lopdf 0.41.0` (locked in `Cargo.lock`)
- pulled in by `pdf-inspector 0.1.7`, which is used by the anydoc
document-reading path (`pdf-inspector` declares `lopdf` and resolves
the vulnerable version)
### Reproduction (from a clean checkout)
1. `git clone` the repository and check out `main`.
2. Run `cargo audit` (or `cargo deny check advisories`).
3. Observed: `error[vulnerability]: Stack overflow in lopdf via deeply
nested PDF objects / lopdf 0.41.0` — exit code 1.
### Suggested fix
Upgrade `pdf-inspector` from 0.1.7 to 0.1.8, which raises its `lopdf`
requirement to >= 0.42.0 and resolves the advisory. No application
source changes are needed. I have a patch ready and will open a PR
referencing this issue.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Start with Cargo.lock and reproduce the advisory using cargo audit or cargo deny check advisories. Check the pdf-inspector dependency in the anydoc document-reading path, then verify that the locked lopdf version is no longer affected and the advisory check passes.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- rust
- Domaine
- build-system, security
- Type d'issue
- Bug
- Difficulté
- 1/5
- Temps estimé
- 1-3 heures
- Activité
- Active
- Clarté
- Clairement spécifiée
- Accessibilité débutants
- 35/100