Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-12600— Uncontrolled memory usage in Innodata Labs’ Poppler JPX decoderUncontrolled memory usage in Innodata Labs’ Poppler JPX decoder

Quick assessment

Affected
Poppler Innodata Labs
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在由 Innodata Labs 开发的 Poppler 分支的内部 JPEG2000(JPX)解码实现中存在拒绝服务(DoS)漏洞。当应用程序处理包含特殊构造的 JPXDecode 图像的不可信 PDF 文件时,远程攻击者可导致不受控制的内存消耗。该缺陷出现在 JPXStream::readCodestream() 函数中,来自 SIZ 段(例如 img.nComps)的、由外部控制的数据被用于分配瓦片(tiles)和分量(components)的内存,但未进行充分的验证。攻击者可借此迫使系统过度分配内存,从而导

CVSS 8.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12600

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Uncontrolled memory usage in Innodata Labs’ Poppler JPX decoderUncontrolled memory usage in Innodata Labs’ Poppler JPX decoder
Source: CVE Program / CVE List V5
Vulnerability Description
Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF file containing specially crafted JPXDecode images, a remote attacker can cause uncontrolled memory consumption. The flaw occurs in the JPXStream::readCodestream() function, where values controlled from the SIZ segment (such as img.nComps) are used for the memory allocation of tiles and components without adequate validation. This allows an attacker to force excessive memory allocation and cause a resource exhaustion, ultimately causing the pdftoppm process to terminate due to out-of-memory (OOM) conditions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Poppler Innodata Labs 0 ~ 25/08/2026 -

II. Public POCs for CVE-2026-12600

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12600

登录查看更多情报信息。

Vendor Advisories for CVE-2026-12600 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-12600

No comments yet


Leave a comment