A denial of service flaw was found in Poppler's Splash backend. (CVE-2026-93653)
A denial of service vulnerability exists in Poppler's Splash backend where a crafted PDF with specific tiling-pattern geometry can cause an unbounded CPU loop. This flaw leads to 100% CPU consumption for an extended period when rendering malicious PDFs. The issue arises from an attacker-controlled repeat count in the pattern-fill routine without corresponding memory allocation. This affects applications using Poppler's Splash backend to render untrusted PDFs.
AI Analysis
Technical Summary
CVE-2026-93653 describes a denial of service flaw in Poppler's Splash backend. A specially crafted PDF with tiling-pattern geometry near the int32 boundary causes SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count, resulting in an excessively long loop in the pattern-fill scanline routine. This loop consumes 100% CPU without allocating additional memory, allowing an attacker to cause prolonged resource exhaustion by supplying a malicious PDF to an application that uses Poppler's Splash backend for rendering.
Potential Impact
The vulnerability causes a denial of service by consuming excessive CPU resources during PDF rendering. Applications that process untrusted PDFs with Poppler's Splash backend can be forced into an unbounded CPU loop, significantly degrading system performance or causing service disruption. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
Red Hat advises avoiding opening or processing untrusted PDF files with applications that rely on Poppler's Splash backend to mitigate this issue. No official patch or fix is explicitly stated in the advisory, so operational controls to restrict untrusted PDF processing are recommended until a fix is available. Check vendor advisories for updates on patch availability.
A denial of service flaw was found in Poppler's Splash backend. (CVE-2026-93653)
Description
A denial of service vulnerability exists in Poppler's Splash backend where a crafted PDF with specific tiling-pattern geometry can cause an unbounded CPU loop. This flaw leads to 100% CPU consumption for an extended period when rendering malicious PDFs. The issue arises from an attacker-controlled repeat count in the pattern-fill routine without corresponding memory allocation. This affects applications using Poppler's Splash backend to render untrusted PDFs.
CVSS v3.1
Score 5.5medium
Affected software
pkg:deb/ubuntu/poppler?arch=source&distro=esm-infra/xenialpkg:deb/ubuntu/poppler?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/poppler?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/poppler?arch=source&distro=jammypkg:deb/ubuntu/poppler?arch=source&distro=noblepkg:deb/ubuntu/poppler?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93653 describes a denial of service flaw in Poppler's Splash backend. A specially crafted PDF with tiling-pattern geometry near the int32 boundary causes SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count, resulting in an excessively long loop in the pattern-fill scanline routine. This loop consumes 100% CPU without allocating additional memory, allowing an attacker to cause prolonged resource exhaustion by supplying a malicious PDF to an application that uses Poppler's Splash backend for rendering.
Potential Impact
The vulnerability causes a denial of service by consuming excessive CPU resources during PDF rendering. Applications that process untrusted PDFs with Poppler's Splash backend can be forced into an unbounded CPU loop, significantly degrading system performance or causing service disruption. There is no impact on confidentiality or integrity, only availability is affected.
Mitigation Recommendations
Red Hat advises avoiding opening or processing untrusted PDF files with applications that rely on Poppler's Splash backend to mitigate this issue. No official patch or fix is explicitly stated in the advisory, so operational controls to restrict untrusted PDF processing are recommended until a fix is available. Check vendor advisories for updates on patch availability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-93653
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be2cf7a7c54106eeec06
Added to database: 09/24/2026, 06:07:40 UTC
Last enriched: 09/24/2026, 06:23:06 UTC
Last updated: 09/25/2026, 02:47:33 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.