---
id: CVE-2026-10118
title: A flaw was found in Poppler's Splash backend
summary: >-
  A flaw was found in Poppler's Splash backend. A remote attacker could exploit
  this vulnerability by crafting a malicious PDF file that, when rendered,
  triggers an integer overflow in the `tilingPatternFill` function. This
  overflow leads …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
vendor: Red Hat
product: poppler
affected:
  - poppler (all versions)
  - poppler (all versions)
  - compat-poppler022 (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - poppler (all versions)
  - rhaiis/model-opt-cuda-rhel9 (all versions)
  - rhaiis/vllm-spyre-rhel9 (all versions)
  - rhaiis/vllm-rocm-rhel9 (all versions)
  - rhaiis/vllm-cuda-rhel9 (all versions)
  - poppler-main (all versions)
  - rhai/base-image-neuron-rhel9 (all versions)
  - poppler
published: '2026-06-01'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T03:16:39.240'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10118'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:24984'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:24985'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:25058'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27720'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27721'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27722'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27723'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27724'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27725'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:27727'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:29952'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30044'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30078'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30087'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30088'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30089'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:30134'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:74674'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-10118'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2460428'
    label: secalert@redhat.com
  - url: 'https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1715'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:24984'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24985'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25058'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27720'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27721'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27722'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27723'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27724'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27725'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:27727'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:29952'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30044'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30078'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30087'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30088'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30089'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30134'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-10118'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2460428'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10118.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
  - cve.org
epss: 0.00252
epssPercentile: 0.15139
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-02T00:00:00+00:00'
ingestedAt: '2026-10-02T03:07:53.993Z'
---

## Overview

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
