216.73.216.123

CVE-2026-10118

· Published 01/06/2026 17:16 · Modified 01/06/2026 18:12

Labels: CVE-2026-10118 2026-06-01CVE-2026-10118CWE-190[email protected]

Essential information

Published
01/06/2026 17:16
Modified
01/06/2026 18:12
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
poppler / poppler cpe:2.3:a:poppler:poppler:*:*:*:*:*:*:*:*

References