CVE-2025-43903: Freedesktop Poppler
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.
Affected products
- Freedesktop Poppler: before 25.04.0 (fixed in 25.04.0)
Published 2025-04-18. Last modified 2026-06-17.