CVE-2020-10223: Gonitro Nitro Pro

High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document.

Affected products

  • Gonitro Nitro Pro: before 13.13.2.242 (fixed in 13.13.2.242)

Published 2020-03-08. Last modified 2026-06-17.