CVE-2025-43903: Freedesktop Poppler

Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.

NSSCryptoSignBackend.cc in Poppler before 25.04.0 does not verify the adbe.pkcs7.sha1 signatures on documents, resulting in potential signature forgeries.

Affected products

Published 2025-04-18. Last modified 2026-06-17.