CVE-2026-4407: Out-of-bounds array write in Xpdf 4.06 due to missing validation
Published Mar 18, 2026
·Updated
Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color spaces.
Affected Software
1 affected component
xpdf Xpdf<4.06
Event History
Mar 18, 2026
CVE Published
via MITRE·09:44 PM
Data Sourced
via MITRE·09:44 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Mar 31, 58197
Event
via FIRST·10:28 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-4407?
CVE-2026-4407 is considered a high-severity vulnerability due to the potential for out-of-bounds array write leading to application crashes or arbitrary code execution.
2
How do I fix CVE-2026-4407?
To fix CVE-2026-4407, upgrade to Xpdf version 4.07 or later where the vulnerability has been addressed.
3
What software is affected by CVE-2026-4407?
CVE-2026-4407 affects Xpdf version 4.06 and earlier.
4
What type of vulnerability is CVE-2026-4407?
CVE-2026-4407 is classified as an out-of-bounds write vulnerability.
5
What could exploit CVE-2026-4407?
Exploitation of CVE-2026-4407 could potentially lead to crashes or the execution of arbitrary code in vulnerable Xpdf applications.