CVE-2026-93312
Freedesktop Poppler JBIG2Stream.cc rewind null pointer dereference
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version 26.08.0 is recommended to address this issue. Patch name: 5e49250f13b0390edeb3f90eb4c02c9941f97067. Upgrading the affected component is advised.
| CWE | CWE-476 CWE-404 |
| Vendor | freedesktop |
| Product | poppler |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for freedesktop poppler
Be the first to know when new medium vulnerabilities affecting freedesktop poppler are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Freedesktop / Poppler
26.07.0
References
vuldb.com: https://vuldb.com/vuln/406610 vuldb.com: https://vuldb.com/vuln/406610/cti vuldb.com: https://vuldb.com/cve/CVE-2026-93312 vuldb.com: https://vuldb.com/submit/942345 gitlab.freedesktop.org: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759 gitlab.freedesktop.org: https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2314 github.com: https://github.com/r1ck9-2q/cve_summit/blob/main/Null-pointer-offset-undefined-behavior-in-JBIG2Stream-rewind-JBIG2Stream.cc-1229.md gitlab.freedesktop.org: https://gitlab.freedesktop.org/poppler/poppler/-/commit/5e49250f13b0390edeb3f90eb4c02c9941f97067
Credits
๐ r1ck99 (VulDB User)