Vulnerability Description
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Podofo Project | Podofo | >= 0.10.0, <= 0.10.5 |
Related Weaknesses (CWE)
References
- https://github.com/ShadowByte1/CVE-Reports/blob/main/CVE-2025-46205.mdExploitThird Party Advisory
- https://github.com/ShadowByte1/CVE-Reports/issues/1
- https://github.com/podofo/podofoProduct
FAQ
What is CVE-2025-46205?
CVE-2025-46205 is a vulnerability with a CVSS score of 8.1 (HIGH). A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is dispu...
How severe is CVE-2025-46205?
CVE-2025-46205 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-46205?
Check the references section above for vendor advisories and patch information. Affected products include: Podofo Project Podofo.