Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-10118

29
FAUCET Score

A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

First published: Jun 1, 2026Last modified: Jun 27, 2026

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Enterprise Linux 8
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Range not provided by sourceCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Range not provided by sourceCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 16th percentile among its peer group of 11,621 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

ubuntupatch availablevia ubuntu_usn
Product: poppler (jammy)Fixed in: 22.02.0-2ubuntu0.13
ubuntupatch availablevia ubuntu_usn
Product: poppler (noble)Fixed in: 24.02.0-1ubuntu9.9
ubuntupatch availablevia ubuntu_usn
Product: poppler (questing)Fixed in: 25.03.0-10ubuntu0.2
ubuntupatch availablevia ubuntu_usn
Product: poppler (resolute)Fixed in: 26.01.0-2ubuntu0.1

Vendor Advisories (1)

ubuntuUSN-8400-1

poppler vulnerability

Jun 8, 2026

References

security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-10118.json
access.redhat.com / errata/RHSA-2026:24984
access.redhat.com / errata/RHSA-2026:24985
access.redhat.com / errata/RHSA-2026:25058
access.redhat.com / errata/RHSA-2026:27720
access.redhat.com / errata/RHSA-2026:27721
access.redhat.com / errata/RHSA-2026:27722
access.redhat.com / errata/RHSA-2026:27723
access.redhat.com / errata/RHSA-2026:27724
access.redhat.com / errata/RHSA-2026:27725
access.redhat.com / errata/RHSA-2026:27727
access.redhat.com / errata/RHSA-2026:29952
access.redhat.com / errata/RHSA-2026:30044
access.redhat.com / errata/RHSA-2026:30078
access.redhat.com / errata/RHSA-2026:30087
access.redhat.com / errata/RHSA-2026:30088
access.redhat.com / errata/RHSA-2026:30089
access.redhat.com / errata/RHSA-2026:30134
access.redhat.com / security/cve/CVE-2026-10118
bugzilla.redhat.com / show_bug.cgi
gitlab.freedesktop.org / poppler/poppler/-/work_items/1715