PT-2026-40963 · Podofo · Podofo

·

CVE-2026-44348

·

Published

2026-05-14

·

Updated

2026-06-09

CVSS v3.1

2.5

Low

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions PoDoFo versions 1.0.0 through 1.0.3
Description A double-free issue exists in the compute hash to sign() function within the src/podofo/private/OpenSSLInternal Ripped.cpp file. If the EVP DigestFinal function fails after the buf variable has been freed, the Error label triggers a second free of buf, leading to heap corruption (a condition where the memory allocator's internal structures are damaged).
Recommendations Update to version 1.0.4.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44348
GHSA-8FQ6-RQPV-XQ72
OPENSUSE-SU-2026:10970-1
SUSE-SU-2026:2309-1

Affected Products

Podofo