HIGH
Poppler
CVE published 2026-08-25
CVE-2026-12600
A denial-of-service (DoS) vulnerability exists in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. The vulnerability occurs in the JPXStream::readCodestream() function, where values controlled from the SIZ segment are used for memory allocation without adequate validation, allowing an attacker to cause uncontrolled memory consumption.