Numeric Errors Affecting poppler package, versions *


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.32% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-POPPLER-19920338
  • published18 Sept 2026
  • disclosed18 Sept 2026

Introduced: 18 Sep 2026

NewCVE-2026-93311  (opens in a new tab)
CWE-189  (opens in a new tab)
CWE-190  (opens in a new tab)

How to fix?

There is no fixed version for Echo:latest poppler.

NVD Description

Note: Versions mentioned in the description apply only to the upstream poppler package and not the poppler package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSample results in integer overflow. The attack may be performed from remote. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

CVSS Base Scores

version 3.1