Denial-of-Service Vulnerability in Poppler Product by Innodata Labs
CVE-2026-12600
8.7HIGH
What is CVE-2026-12600?
A vulnerability exists in the JPEG2000 decoding implementation of Poppler, where the JPXStream::readCodestream() function processes untrusted PDF files containing specially crafted JPXDecode images. This flaw allows a remote attacker to manipulate the SIZ segment to induce excessive memory allocation, leading to uncontrolled memory consumption and potentially terminating the pdftoppm process due to out-of-memory conditions. Proper validation measures are critical to mitigate this risk.
Affected Version(s)
Innodata Labs 0 < 25/08/2026
