PT-2026-29438 · Pdf · Pdf

Suyue Guo

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-3778

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Multiple / Unspecified Products (affected versions not specified)
Description The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference each other in a loop, passing the document to APIs (e.g., SOAP) that perform deep traversal can cause uncontrolled recursion, stack exhaustion, and application crashes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2026-3778

Affected Products

Pdf