JLSEC-2026-1194 Low 2.9
An issue was discovered in freedesktop poppler v25.04.0. The heap memory containing PDF stream...
An issue was discovered in freedesktop poppler v25.04.0. The heap memory containing PDF stream objects is not cleared upon program exit, allowing attackers to obtain sensitive PDF content via a memory dump.
References
- http://freedesktop.com
- http://poppler.com
- https://github.com/Landw-hub/CVE-2025-50422
- https://github.com/advisories/GHSA-6f98-2v97-grfv
- https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621
- https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591
- https://gitlab.freedesktop.org/poppler/poppler/-/issues/1591#note_3045081
- https://nvd.nist.gov/vuln/detail/CVE-2025-50422