Changeflow GovPing Data Privacy & Cybersecurity Xpdf Vulnerability Allows Denial of Service
Routine Notice Added Final

Xpdf Vulnerability Allows Denial of Service

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 18th, 2026
Detected March 19th, 2026
Email

Summary

CERT-Bund has issued a security advisory regarding a denial-of-service vulnerability in the Xpdf PDF viewer. The vulnerability affects versions of Xpdf on Linux, UNIX, and Windows systems. The advisory provides information on the vulnerability and mitigation, noting a CVSS base score of 2.9.

What changed

CERT-Bund has published a security advisory (WID-SEC-2026-0786) detailing a denial-of-service vulnerability in the Xpdf PDF viewer, specifically affecting version 4.06. The vulnerability can be exploited by a local attacker and has a CVSS base score of 2.9. The advisory applies to Xpdf installations on Linux, UNIX, and Windows operating systems.

While this is a security advisory and not a regulatory mandate, organizations using Xpdf should be aware of this vulnerability. Users are advised to check for updated versions or apply any available mitigations once released by the vendor to prevent potential denial-of-service disruptions. The advisory does not specify a compliance deadline, but prompt review of security updates is recommended.

What to do next

  1. Review Xpdf installations for version 4.06.
  2. Monitor for vendor-released patches or mitigation guidance.

Source document (simplified)

[WID-SEC-2026-0786] xpdf: Schwachstelle ermöglicht Denial of Service CVSS Base Score 2.9 (niedrig) CVSS Temporal Score 2.7 (niedrig) Remoteangriff nein Datum 18.03.2026 Stand 19.03.2026 Mitigation nein

Betroffene Systeme

Betriebssystem

  • Linux
  • UNIX
  • Windows

Produktbeschreibung

Mit Xpdf können PDF-Dokumente betrachtet werden. Dieser PDF-Betrachter ist zudem auch für Microsoft Windows verfügbar.

Produkte

18.03.2026
- Open Source xpdf 4.06

Angriff

Angriff

Ein lokaler Angreifer kann eine Schwachstelle in xpdf ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 18th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
WID-SEC-2026-0786

Who this affects

Applies to
Employers Technology companies
Industry sector
5112 Software & Technology
Activity scope
Software Usage
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities Denial of Service Attacks

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.