On October 7, 2026, the Ubuntu Security feed published notice USN-8894-1 on vulnerabilities in Poppler, a set of libraries for rendering and processing PDF files. The notice, automatically translated, lists five CVEs. According to the text, an attacker could possibly exploit these flaws to make Poppler crash, causing denial of service, and in some cases execute arbitrary code.
The five items are: CVE-2026-102620, integer overflow in FoFiTrueType::cvtSfnts; CVE-2026-102621, integer overflow in SplashClip::clipToPath; CVE-2026-93312, null pointer dereference in JBIG2Stream, with impact described only as denial of service; CVE-2026-93313, integer overflow in JBIG2Stream::readCodeTableSeg; and CVE-2026-93314, integer overflow in FoFiTrueType::mapCodeToGID.
The relevance for anyone processing documents is that Poppler is often triggered when opening PDFs received from third parties. To verify the scope, consult the original notice on the Ubuntu site using the identifier USN-8894-1, check which package versions are affected in your distribution, and compare them with the versions installed on your servers and workstations.