Skip to content

[Security]: RUSTSEC-2026-0187: lopdf 0.41.0 in Cargo.lock (stack overflow via deeply nested PDF objects) #2586

Description

@1688mengdie

Summary

cargo audit reports a vulnerability in the locked lopdf dependency:
RUSTSEC-2026-0187 (stack overflow when parsing deeply nested PDF
objects, CVSS 7.5). Cargo.lock on main pins lopdf 0.41.0, which is
within the affected range; the advisory is fixed in lopdf >= 0.42.0.

Affected dependency chain

  • lopdf 0.41.0 (locked in Cargo.lock)
  • pulled in by pdf-inspector 0.1.7, which is used by the anydoc
    document-reading path (pdf-inspector declares lopdf and resolves
    the vulnerable version)

Reproduction (from a clean checkout)

  1. git clone the repository and check out main.
  2. Run cargo audit (or cargo deny check advisories).
  3. Observed: error[vulnerability]: Stack overflow in lopdf via deeply nested PDF objects / lopdf 0.41.0 — exit code 1.

Suggested fix

Upgrade pdf-inspector from 0.1.7 to 0.1.8, which raises its lopdf
requirement to >= 0.42.0 and resolves the advisory. No application
source changes are needed. I have a patch ready and will open a PR
referencing this issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions