CVE-2022-34503: Qpdf Project Qpdf

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

Affected products

Published 2022-07-22. Last modified 2026-06-17.