CVE-2018-9918 (https://nvd.nist.gov/vuln/detail/CVE-2018-9918): libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted. @Maintainers version 8.1.0 already in the tree, please confirm this does not affect 7.0.0. If not affected please proceed to clean up vulnerable versions.