PT-2026-81259 · Innodata · Poppler

CVE-2026-12600

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Poppler fork developed by Innodata Labs (affected versions not specified)
Description A denial-of-service issue exists in the internal JPEG2000 (JPX) decoding implementation. A remote attacker can trigger uncontrolled memory consumption by providing a specially crafted PDF file containing JPXDecode images. The flaw is located in the JPXStream::readCodestream() function, where values from the SIZ segment, such as img.nComps, are used for memory allocation of tiles and components without proper validation. This leads to resource exhaustion and causes the pdftoppm process to terminate due to out-of-memory (OOM) conditions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12600

Affected Products

Poppler