CVE-2025-43718: Freedesktop Poppler
Low severity, CVSS 2.9. EPSS: 0.1% chance of exploitation in the next 30 days.
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFEVersion) of a PDF document, e.g., a regular expression for a long pdfsubver string. This occurs in Dict::lookup, Catalog::getMetadata, and associated functions in PDFDoc, with deep recursion in the regex executor (std::__detail::_Executor).
Affected products
- Freedesktop Poppler: from 24.06.1, before 25.04.0 (fixed in 25.04.0)
Published 2025-10-01. Last modified 2026-09-30.