data/reports: add GO-2026-6115 - data/reports/GO-2026-6115.yaml Fixes golang/vulndb#6115 Change-Id: I6d2d3c1f178d9c033adc127121ec2af560513d7c Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/816800 Reviewed-by: Nicholas Husin <nsh@golang.org> Auto-Submit: Ian Alexander <jitsu@google.com> Reviewed-by: Nicholas Husin <husin@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
diff --git a/data/osv/GO-2026-6115.json b/data/osv/GO-2026-6115.json new file mode 100644 index 0000000..e985817 --- /dev/null +++ b/data/osv/GO-2026-6115.json
@@ -0,0 +1,138 @@ +{ + "schema_version": "1.3.1", + "id": "GO-2026-6115", + "modified": "0001-01-01T00:00:00Z", + "published": "0001-01-01T00:00:00Z", + "aliases": [ + "CVE-2026-56867" + ], + "summary": "Multiple denial of service vulnerabilities in rsc.io/pdf and forks", + "details": "The PDF parser in rsc.io/pdf and its downstream forks github.com/ledongthuc/pdf and github.com/dslipak/pdf contains multiple defects when parsing untrusted input:\n\n- Unchecked /Size, /Index, /W, and classic subsection header parameters in cross-reference tables allow crafted values to trigger fatal out-of-memory (OOM) panics.\n- Unterminated hexadecimal strings cause an infinite loop in readByte and readHexString.\n- Cyclic object references (/First, /Parent, /Kids, /Next) in document outlines cause unbounded recursion leading to uncatchable stack overflow.\n- Various malformed constructs trigger runtime panics in NewReader and Page.Content (such as empty graphics state pop 'Q', oversized CMap entries, odd-length UTF-16 strings, and newline buffer underflows).", + "affected": [ + { + "package": { + "name": "rsc.io/pdf", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "rsc.io/pdf", + "symbols": [ + "NewReader", + "NewReaderEncrypted", + "Open", + "Page.Content", + "Reader.Page" + ] + } + ] + } + }, + { + "package": { + "name": "github.com/ledongthuc/pdf", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/ledongthuc/pdf", + "symbols": [ + "NewReader", + "NewReaderEncrypted", + "Open", + "Page.Content", + "Page.GetTextByColumn", + "Page.GetTextByRow", + "Reader.GetPlainText", + "Reader.GetStyledTexts", + "Reader.Page" + ] + } + ] + } + }, + { + "package": { + "name": "github.com/dslipak/pdf", + "ecosystem": "Go" + }, + "ranges": [ + { + "type": "SEMVER", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "ecosystem_specific": { + "imports": [ + { + "path": "github.com/dslipak/pdf", + "symbols": [ + "NewReader", + "NewReaderEncrypted", + "Open", + "Page.Content", + "Reader.Page" + ] + } + ] + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56867" + }, + { + "type": "REPORT", + "url": "https://github.com/golang/vulndb/issues/6115" + }, + { + "type": "WEB", + "url": "https://github.com/ledongthuc/pdf/pull/78" + }, + { + "type": "WEB", + "url": "https://github.com/rsc/pdf" + }, + { + "type": "WEB", + "url": "https://github.com/dslipak/pdf" + } + ], + "credits": [ + { + "name": "Gage Marshall" + } + ], + "database_specific": { + "url": "https://pkg.go.dev/vuln/GO-2026-6115", + "review_status": "REVIEWED" + } +} \ No newline at end of file
diff --git a/data/reports/GO-2026-6115.yaml b/data/reports/GO-2026-6115.yaml new file mode 100644 index 0000000..a4a9e85 --- /dev/null +++ b/data/reports/GO-2026-6115.yaml
@@ -0,0 +1,69 @@ +id: GO-2026-6115 +modules: + - module: rsc.io/pdf + vulnerable_at: 0.1.1 + packages: + - package: rsc.io/pdf + symbols: + - Open + - NewReader + - NewReaderEncrypted + - Reader.Page + - Page.Content + skip_fix: repository is archived + - module: github.com/ledongthuc/pdf + vulnerable_at: 0.0.0-20250511090121-5959a4027728 + packages: + - package: github.com/ledongthuc/pdf + symbols: + - Open + - NewReader + - NewReaderEncrypted + - Reader.Page + - Page.Content + - Reader.GetPlainText + - Reader.GetStyledTexts + - Page.GetTextByColumn + - Page.GetTextByRow + skip_fix: no fix available + - module: github.com/dslipak/pdf + vulnerable_at: 0.0.2 + packages: + - package: github.com/dslipak/pdf + symbols: + - Open + - NewReader + - NewReaderEncrypted + - Reader.Page + - Page.Content + skip_fix: no fix available +summary: Multiple denial of service vulnerabilities in rsc.io/pdf and forks +description: |- + The PDF parser in rsc.io/pdf and its downstream forks github.com/ledongthuc/pdf + and github.com/dslipak/pdf contains multiple defects when parsing untrusted + input: + + - Unchecked /Size, /Index, /W, and classic subsection header parameters in + cross-reference tables allow crafted values to trigger fatal out-of-memory + (OOM) panics. + - Unterminated hexadecimal strings cause an infinite loop in readByte and + readHexString. + - Cyclic object references (/First, /Parent, /Kids, /Next) in document + outlines cause unbounded recursion leading to uncatchable stack overflow. + - Various malformed constructs trigger runtime panics in NewReader and + Page.Content (such as empty graphics state pop 'Q', oversized CMap entries, + odd-length UTF-16 strings, and newline buffer underflows). +cves: + - CVE-2026-56867 +credits: + - Gage Marshall +references: + - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-56867 + - report: https://github.com/golang/vulndb/issues/6115 + - web: https://github.com/ledongthuc/pdf/pull/78 + - web: https://github.com/rsc/pdf + - web: https://github.com/dslipak/pdf +source: + id: go-security-team + created: 2026-08-17T23:16:17.02638-04:00 +review_status: REVIEWED