CVE-2017-18186: Qpdf Project Qpdf

Medium severity, CVSS 5.5. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.

Affected products

Published 2018-02-13. Last modified 2026-06-17.