Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
No fix has been reported as yet for the fork maintained by Innodata Labs. Meanwhile, Poppler has removed the JPX decoder code.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF file containing specially crafted JPXDecode images, a remote attacker can cause uncontrolled memory consumption. The flaw occurs in the JPXStream::readCodestream() function, where values controlled from the SIZ segment (such as img.nComps) are used for the memory allocation of tiles and components without adequate validation. This allows an attacker to force excessive memory allocation and cause a resource exhaustion, ultimately causing the pdftoppm process to terminate due to out-of-memory (OOM) conditions. | |
| Title | Uncontrolled memory usage in Innodata Labs’ Poppler JPX decoderUncontrolled memory usage in Innodata Labs’ Poppler JPX decoder | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-08-25T13:10:20.470Z
Reserved: 2026-06-18T10:33:39.525Z
Link: CVE-2026-12600
Updated: 2026-08-25T13:10:15.431Z
Status : Received
Published: 2026-08-25T11:16:50.383
Modified: 2026-08-25T13:17:48.543
Link: CVE-2026-12600
No data.
OpenCVE Enrichment
Updated: 2026-08-25T12:45:17Z
-
CWE-400
Uncontrolled Resource Consumption