Podofo is a lightweight open-source PDF manipulation library embedded across document-processing applications and tools, giving its vulnerability footprint broader downstream relevance than its single-product scope might suggest. The vendor's disclosures cluster around memory-safety and bounds-checking weaknesses—null-pointer dereferences, out-of-bounds reads and writes, and infinite-loop conditions—reflecting the parsing complexity inherent to PDF format handling and the demands of a C++-based codebase operating on untrusted input. These weakness classes are characteristic of low-level document processors and can surface across any application that integrates the library, making remediation dependent on downstream vendors rebuilding and redistributing. Defenders should inventory applications that bundle Podofo rather than the library alone, monitor vendor releases for parser-related fixes, and treat PDF processing from untrusted sources as a potential exposure vector; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Podofo Project over time
Signals from CVEs in this vendor scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8002HIGH In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers cou | Mar 9, 2018 | 8.8 | 42 | NO | YES |
CVE-2017-8378CRITICAL Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or | May 1, 2017 | 9.8 | 31 | NO | NO |
CVE-2018-8000HIGH In PoDoFo 0.9.5, there exists a heap-based buffer overflow vulnerability in PoDoFo::PdfTokenizer::GetNextToken() in PdfTokenizer.cpp, a related issue to CVE-2017-5886. Remote attac | Mar 9, 2018 | 8.8 | 29 | NO | NO |
CVE-2025-46205HIGH A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) by supplying a crafted PDF file. | Oct 1, 2025 | 8.1 | 27 | NO | NO |
CVE-2023-31568HIGH Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4. | May 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-31567HIGH Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3. | May 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-31566HIGH Podofo v0.10.0 was discovered to contain a heap-use-after-free via the component PoDoFo::PdfEncrypt::IsMetadataEncrypted(). | May 10, 2023 | 8.8 | 27 | NO | NO |
CVE-2018-19532HIGH A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by p | Nov 26, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-8787HIGH The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function in base/PdfXRefStreamParserObject.cpp:224 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service ( | May 5, 2017 | 8.8 | 27 | NO | NO |
CVE-2018-20751HIGH An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the | Feb 4, 2019 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (63 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Podofo Project.
Media articles that mention a CVE ID that affects a product developed by Podofo Project — matched by CVE ID, not by vendor name.