Disclosure summary
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer overflow. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading to version 26.09.0 is able to address this issue. The name of the patch is 323c91036d99926a8b90dc14329f7b40aece22f8. It is recommended to upgrade the affected component.
Source-reported weakness categories
CWE-189, CWE-190
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-102621
Open original source · Updated Sep 30, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
- NIST NVD record
- CVE Program record
- github.com
- gitlab.freedesktop.org
- gitlab.freedesktop.org
- gitlab.freedesktop.org
- vuldb.com
- vuldb.com
- vuldb.com
- vuldb.com
PUBLISHED 2026-09-29T18:17:07-04:00
MODIFIED 2026-09-30T16:17:22-04:00
INGESTED 2026-10-06T11:43:05-04:00