Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32053 | Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated functions in PDFDoc, with deep recursion in the regex executor (std::__detail::_Executor). |
Ubuntu USN |
USN-7803-1 | poppler vulnerability |
Fri, 03 Oct 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 03 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | poppler: Poppler stack overflow | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 02 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 02 Oct 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Poppler
Poppler poppler |
|
| Vendors & Products |
Poppler
Poppler poppler |
Wed, 01 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-674 | |
| Metrics |
cvssV3_1
|
Wed, 01 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated functions in PDFDoc, with deep recursion in the regex executor (std::__detail::_Executor). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-06T17:41:43.699Z
Reserved: 2025-04-17T00:00:00.000Z
Link: CVE-2025-43718
Updated: 2025-10-01T19:16:13.911Z
Status : Deferred
Published: 2025-10-01T19:15:35.683
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-43718
OpenCVE Enrichment
Updated: 2025-10-02T08:45:50Z
EUVD
Ubuntu USN