{"id":"GO-2026-5781","title":"Uncatchable stack-overflow denial of service in rsc.io/pdf","summary":"Uncatchable stack-overflow denial of service in rsc.io/pdf","severity":"none","vendor":"pdf","product":"rsc.io/pdf","ecosystem":"go","affected":["rsc.io/pdf"],"published":"2026-07-27","updated":"2026-07-27","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GO-2026-5781","references":[{"url":"https://github.com/golang/vulndb/issues/5781"},{"url":"https://github.com/rsc/pdf"}],"tags":["osv","go"],"ingestedAt":"2026-07-27T19:08:55.942Z","slug":"GO-2026-5781","body":"## Overview\n\npdf.Open and PDF object resolution in rsc.io/pdf recurse without bound on nested arrays and dictionaries. A sufficiently deeply nested document exhausts the goroutine stack limit and triggers a fatal, uncatchable stack overflow. Any service that parses untrusted PDFs with rsc.io/pdf can therefore be taken down by a single small input.\n\n## Affected packages\n\n- `rsc.io/pdf`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}