CVE-2026-93312Medium· 4.3▾ SunlitA flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93653Medium· 5.5A denial of service flaw was found in Poppler's Splash backend
CVE-2026-93313Medium· 6.3A vulnerability was found in Freedesktop Poppler 26.07.0
CVE-2026-93311Medium· 4.3A vulnerability was detected in Freedesktop Poppler 26.07.0
CVE-2026-93314Medium· 6.3A vulnerability was determined in Freedesktop Poppler 26.07.0
CVE-2026-92417Medium· 6.5A vulnerability was found in Open5GS up to 2.8.0
CVE-2026-92413Medium· 4.3A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9