CVE-2026-93313

Source
https://cve.org/CVERecord?id=CVE-2026-93313
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93313.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93313
Downstream
Published
2026-09-18T01:15:13Z
Modified
2026-09-19T08:03:44Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Freedesktop Poppler JBIG2Stream.cc readCodeTableSeg integer overflow
Details

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named eb87cf711563894649bd0c365baa479401dc6d51. To fix this issue, it is recommended to deploy a patch.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-189",
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93313.json"
}
References

Affected packages

Git / gitlab.freedesktop.org/poppler/poppler

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/poppler/poppler
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "26.07.0"
        },
        {
            "last_affected": "26.07.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

26.*
26.07.0
poppler-26.*
poppler-26.07.0
poppler-26.08.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93313.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "123191503843309014676462592683827693963",
                "264628510904604181078089425962132481800",
                "13908660269154343819994948039017565382",
                "128106233243259619208070127659920503566"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-93313-6edc37cd",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://gitlab.freedesktop.org/poppler/poppler@eb87cf711563894649bd0c365baa479401dc6d51",
        "target": {
            "file": "poppler/JBIG2Stream.cc"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "261361320074877017150607649183982724017",
            "length": 2446
        },
        "id": "CVE-2026-93313-84251191",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitlab.freedesktop.org/poppler/poppler@eb87cf711563894649bd0c365baa479401dc6d51",
        "target": {
            "file": "poppler/JBIG2Stream.cc",
            "function": "JBIG2Stream::readCodeTableSeg"
        }
    }
]
vanir_signatures_modified
"2026-09-19T08:03:44Z"