Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 14 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFinal fails after buf has already been freed, the Error label frees buf a second time, causing heap corruption. This vulnerability is fixed in 1.0.4. | |
| Title | PoDoFo: Double-free vulnerability in compute_hash_to_sign() | |
| Weaknesses | CWE-415 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T18:00:18.245Z
Reserved: 2026-05-05T19:52:59.148Z
Link: CVE-2026-44348
Updated: 2026-05-14T18:00:07.338Z
Status : Deferred
Published: 2026-05-14T17:16:22.553
Modified: 2026-05-14T18:16:49.800
Link: CVE-2026-44348
No data.
OpenCVE Enrichment
Updated: 2026-05-14T19:00:13Z