CVE-2026-10118High· 7.8▾ TwilightA flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the tilingPatternFill function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102621Low· 3.3A vulnerability was identified in Freedesktop Poppler up to 26.08.0
CVE-2026-102620Low· 3.3A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0
CVE-2026-93313Medium· 6.3A vulnerability was found in Freedesktop Poppler 26.07.0
CVE-2026-93311Medium· 4.3A vulnerability was detected in Freedesktop Poppler 26.07.0
CVE-2026-93314Medium· 6.3A vulnerability was determined in Freedesktop Poppler 26.07.0
CVE-2026-88372High· 7.5libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.