Expired Pointer Dereference Affecting ippsample package, versions *


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.24% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-IPPSAMPLE-19222750
  • published23 Aug 2026
  • disclosed21 Aug 2026

Introduced: 21 Aug 2026

NewCVE-2026-77220  (opens in a new tab)
CWE-825  (opens in a new tab)

How to fix?

There is no fixed version for Echo:latest ippsample.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ippsample package and not the ippsample package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data.

CVSS Base Scores

version 3.1