CVE-2025-46205: Podofo Project Podofo
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. NOTE: this is disputed by the Supplier because there is no available file to reproduce the issue.
Affected products
- Podofo Project Podofo: from 0.10.0, up to and including 0.10.5
Published 2025-10-01. Last modified 2026-06-17.