JLSEC-2026-1194

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1194.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1194.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1194
Upstream
  • EUVD-2025-23528
  • GHSA-6f98-2v97-grfv
Published
2026-08-07T17:08:02.500Z
Modified
2026-08-07T17:28:41.194635492Z
Severity
  • 2.9 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
An issue was discovered in freedesktop poppler v25.04.0. The heap memory containing PDF stream...
Details

An issue was discovered in freedesktop poppler v25.04.0. The heap memory containing PDF stream objects is not cleared upon program exit, allowing attackers to obtain sensitive PDF content via a memory dump.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "database_specific": {
                "status": "Deferred"
            },
            "id": "CVE-2025-50422",
            "published": "2025-08-04T17:15:30.813Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-50422",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-50422",
            "modified": "2026-06-17T09:35:04.097Z",
            "imported": "2026-08-06T14:01:06.500Z"
        },
        {
            "id": "GHSA-6f98-2v97-grfv",
            "published": "2025-08-04T18:30:37Z",
            "url": "https://api.github.com/advisories/GHSA-6f98-2v97-grfv",
            "html_url": "https://github.com/advisories/GHSA-6f98-2v97-grfv",
            "modified": "2025-08-10T03:31:36Z",
            "imported": "2026-08-06T14:01:06.257Z"
        },
        {
            "id": "EUVD-2025-23528",
            "published": "2025-08-04T00:00:00Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-23528",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23528",
            "modified": "2025-08-26T18:48:32Z",
            "imported": "2026-08-06T14:01:04.642Z"
        }
    ]
}
References

Affected packages

Julia / Cairo_NoGPL_jll

Package

Name
Cairo_NoGPL_jll
Purl
pkg:julia/Cairo_NoGPL_jll?uuid=a683250b-caed-589c-a637-5aa540466d33

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1194.json"

Julia / Cairo_jll

Package

Name
Cairo_jll
Purl
pkg:julia/Cairo_jll?uuid=83423d85-b0ee-5818-9007-b63ccbeb887a

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1194.json"