PatchSiren

Poppler CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Poppler CVE published 2026-08-25

CVE-2026-12600

A denial-of-service (DoS) vulnerability exists in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. The vulnerability occurs in the JPXStream::readCodestream() function, where values controlled from the SIZ segment are used for memory allocation without adequate validation, allowing an attacker to cause uncontrolled memory consumption.