Poppler is a PDF rendering library. Versions prior to 25.06.0 use std::atomic_int for reference counting. Because std::atomic_int is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.
{
"license": "CC-BY-4.0",
"sources": [
{
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-52886",
"id": "CVE-2025-52886",
"modified": "2025-11-04T22:16:20.887Z",
"imported": "2026-04-13T04:14:33.309Z",
"published": "2025-07-02T16:15:28.933Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-52886"
},
{
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19742",
"id": "EUVD-2025-19742",
"modified": "2025-11-04T22:06:42Z",
"imported": "2026-04-13T04:14:34.608Z",
"published": "2025-07-02T15:46:49Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-19742"
}
]
}