CVE-2026-10118
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when
CVSS
7.8
High
EPSS
0.3%
p16
KEV
—
Exploit Today
5
0-100
Published: Jun 1, 2026 · Last modified: Jul 21, 2026 · CWE-190
0.3%EPSS · 30 days0.3%
2026-08-012026-08-28
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24984
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:24985
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25058
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27720
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27721
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27722
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27723
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27724
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27725
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:27727
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:29952
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30044
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30078
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30087
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30088
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30089
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:30134
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-10118
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2460428
- gitlab.freedesktop.orghttps://gitlab.freedesktop.org/poppler/poppler/-/work_items/1715
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-547559.6 CRI—
——0Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckValid100Params. Royalty payout paths in core/kapp/accounts/accounts.go, core/kapp/market/market.go, and core/kapp/ito/ito.go then credit each oversized split amount and silently discard a negative remainder, allowing ordinary asset transfers, marketplace purchases, or ITO purchases to create unbacked KLV or other assets. This issue is fixed in version 1.7.19.1dCVE-2026-19313—38.8%
——12An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.22hCVE-2026-383507.5 HIG4.4%
——1An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.1dCVE-2026-383497.5 HIG4.4%
——1An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.1dCVE-2026-383487.5 HIG4.4%
——1An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.1dCVE-2026-383467.5 HIG4.4%
——1An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.1d